Plugins bundled with Rhythmbox link to for-sale domain (rhythmbox.org has been drop-caught)

Bug #1887222 reported by Henry Heino
262
This bug affects 2 people
Affects Status Importance Assigned to Milestone
rhythmbox (Ubuntu)
Fix Committed
Low
Unassigned

Bug Description

Plugins bundled with Rhythmbox including "Cover Art Search", "FM Radio", and "Python Console" still link to http://www.rhythmbox.org/. Although http://www.rhythmbox.org/ used to redirect to https://wiki.gnome.org/Apps/Rhythmbox (source: https://web.archive.org/web/20200122080148/http://www.rhythmbox.org/), it now redirects to https://www.dropcatch.com/domain/rhythmbox.org, a site that appears to be selling the domain.

Note: This is my first bug report! I apologize for attaching files that aren't relevant -- I'm still figuring this out! Most relevant is the
PNG attatchment, bugReport.png.

ProblemType: Bug
DistroRelease: Ubuntu 20.04
Package: rhythmbox 3.4.4-1ubuntu2
ProcVersionSignature: Ubuntu 5.4.0-40.44-generic 5.4.44
Uname: Linux 5.4.0-40-generic x86_64
NonfreeKernelModules: wl
ApportVersion: 2.20.11-0ubuntu27.3
Architecture: amd64
CasperMD5CheckResult: skip
CurrentDesktop: ubuntu:GNOME
Date: Sat Jul 11 02:02:53 2020
ExecutablePath: /usr/bin/rhythmbox
InstallationDate: Installed on 2020-03-24 (109 days ago)
InstallationMedia: Ubuntu 19.10 "Eoan Ermine" - Release amd64 (20191017)
ProcEnviron:
 SHELL=/bin/bash
 XDG_RUNTIME_DIR=<set>
 PATH=(custom, user)
 LANG=en_US.UTF-8
SourcePackage: rhythmbox
UpgradeStatus: Upgraded to focal on 2020-06-19 (22 days ago)

Revision history for this message
Henry Heino (personalizedrefrigerator) wrote :
description: updated
Revision history for this message
Henry Heino (personalizedrefrigerator) wrote :

% IANA WHOIS server
% for more information on IANA, visit http://www.iana.org
% This query returned 1 object

refer: whois.pir.org

domain: ORG

organisation: Public Interest Registry (PIR)
address: 1775 Wiehle Avenue
address: Suite 100
address: Reston Virginia 20190
address: United States

contact: administrative
name: Director of Operations, Compliance and Customer Support
organisation: Public Interest Registry (PIR)
address: 1775 Wiehle Avenue
address: Reston Virginia 20190
address: United States
phone: +1 703 889 5778
fax-no: +1 703 889 5779
e-mail: <email address hidden>

contact: technical
name: Senior Director, DNS Infrastructure Group
organisation: Afilias
address: Building 3, Suite 105
address: 300 Welsh Road
address: Horsham, Pennsylvania 19044
address: United States
phone: +1 215.706.5700
fax-no: +1 215.706.5701
e-mail: <email address hidden>

nserver: A0.ORG.AFILIAS-NST.INFO 199.19.56.1 2001:500:e:0:0:0:0:1
nserver: A2.ORG.AFILIAS-NST.INFO 199.249.112.1 2001:500:40:0:0:0:0:1
nserver: B0.ORG.AFILIAS-NST.ORG 199.19.54.1 2001:500:c:0:0:0:0:1
nserver: B2.ORG.AFILIAS-NST.ORG 199.249.120.1 2001:500:48:0:0:0:0:1
nserver: C0.ORG.AFILIAS-NST.INFO 199.19.53.1 2001:500:b:0:0:0:0:1
nserver: D0.ORG.AFILIAS-NST.ORG 199.19.57.1 2001:500:f:0:0:0:0:1
ds-rdata: 17883 7 2 d889cad790f01979e860d6627b58f85ab554e0e491fe06515f35548d1eb4e6ee
ds-rdata: 17883 7 1 38c5cf93b369c7557e0515faaa57060f1bfb12c1

whois: whois.pir.org

status: ACTIVE
remarks: Registration information: http://www.pir.org

created: 1985-01-01
changed: 2020-04-29
source: IANA

Domain Name: RHYTHMBOX.ORG
Registry Domain ID: D402200000014082164-LROR
Registrar WHOIS Server: whois.namebright.com
Registrar URL: http://www.NameBright.com
Updated Date: 2020-07-10T14:36:52Z
Creation Date: 2020-07-10T14:30:36Z
Registry Expiry Date: 2021-07-10T14:30:36Z
Registrar Registration Expiration Date:
Registrar: DropCatch.com 480 LLC
Registrar IANA ID: 1960
Registrar Abuse Contact Email: <email address hidden>
Registrar Abuse Contact Phone: +1.7204960020
Reseller:
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
Domain Status: addPeriod https://icann.org/epp#addPeriod
Registrant Organization: www.DropCatch.com
Registrant State/Province: CO
Registrant Country: US
Name Server: NS1.NAMEBRIGHTDNS.COM
Name Server: NS2.NAMEBRIGHTDNS.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form https://www.icann.org/wicf/)
>>> Last update of WHOIS database: 2020-07-11T09:24:16Z <<<
domain rhythmbox.org not found

description: updated
information type: Private Security → Public Security
summary: - Plugins bundled with Rhythmbox link to for-sale domain
+ Plugins bundled with Rhythmbox link to for-sale domain (rhythmbox.org
+ has been drop-caught)
Revision history for this message
crvi (crvi) wrote :

Please apply the following upstream patch in all "possible" rhythmbox releases.

https://gitlab.gnome.org/GNOME/rhythmbox/-/commit/64c07859c936df1bc739f21b87f7a56e6f8dd161

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in rhythmbox (Ubuntu):
status: New → Confirmed
crvi (crvi)
tags: added: bionic eoan focal trusty xenial
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug report, indeed it seems a change worth backporting to the package but it's also rather low priority since it's not impacting daily usage and the website isn't trying to induce users in error

Changed in rhythmbox (Ubuntu):
importance: Undecided → Critical
importance: Critical → Low
status: Confirmed → In Progress
Changed in rhythmbox (Ubuntu):
status: In Progress → Fix Committed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.