MGASA-2014-0435

    Dashboard / Vulnerabilities / MGASA-2014-0435

    MGASA-2014-0435

    Published: 29 Oct 2014Last Modified: 16 Apr 2026

    Summary: Updated MythTV packages to harden against SSDP reflection attacks

    Details: Updated MythTV packages to harden against SSDP reflection attacks MythTV's UPNP component was suseptable to SSDP reflection attacks and has been hardened to disallow SSDP device discovery from non-local addresses as mitigation. Additionally, a popular schedules retrieval service, Schedules Direct, will deprecate the old URL used by MythTV to retrieve metadata on 1st November 2015. This build of MythTV also updates the URL for this this service for continued operation going forward.

    Affected packages

    Package

    Name: mythtv

    Purl: pkg:rpm/mageia/mythtv?arch=source&distro=mageia-3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.27.4-20141022.1.mga3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High