{"schema_version":"1.7.3","id":"openSUSE-SU-2020:2160-1","published":"2020-12-04T15:24:02Z","modified":"2026-02-04T04:15:30.341261Z","related":["CVE-2020-12695","CVE-2020-28926"],"upstream":["CVE-2020-12695","CVE-2020-28926"],"summary":"Security update for minidlna","details":"This update for minidlna fixes the following issues:\n\nminidlna was updated to version 1.3.0 (boo#1179447)\n\n  - Fixed some build warnings when building with musl.\n  - Use $USER instead of $LOGNAME for the default friendly name.\n  - Fixed build with GCC 10\n  - Fixed some warnings from newer compilers\n  - Disallow negative HTTP chunk lengths. [CVE-2020-28926]\n  - Validate SUBSCRIBE callback URL. [CVE-2020-12695]\n  - Fixed spurious warnings with ogg coverart\n  - Fixed an issue with VLC where browse results would be truncated.\n  - Fixed bookmarks on Samsung Q series\n  - Added DSD file support.\n  - Fixed potential stack smash vulnerability in getsyshwaddr on macOS.\n  - Will now reload the log file on SIGHUP.\n  - Worked around bad SearchCriteria from the Control4 Android app.\n  - Increased max supported network addresses to 8.\n  - Added forced alphasort capability.\n  - Added episode season and number metadata support.\n  - Enabled subtitles by default for unknown DLNA clients, and add enable_subtitles config option.\n  - Fixed discovery when connected to certain WiFi routers.\n  - Added FreeBSD kqueue support.\n  - Added the ability to set the group to run as.\n","affected":[{"package":{"name":"minidlna","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/minidlna&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0-lp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"minidlna":"1.3.0-lp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:2160-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/A2GHF3UJM6D2JSKELXMJY57IRWK3PJM3/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179447"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-12695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-28926"}]}