daap plugin opens port by default

Bug #753986 reported by Marc Deslauriers
270
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Banshee
Fix Released
Medium
banshee (Ubuntu)
Fix Released
Medium
Unassigned
Natty
Fix Released
Undecided
Unassigned

Bug Description

Binary package hint: banshee

In a default installation, the daap plugin is enabled, and listens to port 8089:

tcp 0 0 0.0.0.0:8089 0.0.0.0:* LISTEN

Ubuntu has a "no open ports by default" policy. This needs to be addressed before the Natty release.

ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: banshee 1.9.6-1ubuntu1
ProcVersionSignature: Ubuntu 2.6.38-8.41-generic 2.6.38.2
Uname: Linux 2.6.38-8-generic x86_64
Architecture: amd64
Date: Thu Apr 7 15:37:19 2011
InstallationMedia: Ubuntu 11.04 "Natty Narwhal" - Alpha amd64 (20110302)
ProcEnviron:
 LANGUAGE=en_CA:en
 PATH=(custom, user)
 LANG=en_CA.UTF-8
 SHELL=/bin/bash
SourcePackage: banshee
UpgradeStatus: No upgrade log present (probably fresh install)

Related branches

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :
security vulnerability: no → yes
Changed in banshee:
importance: Unknown → Medium
status: Unknown → Confirmed
Revision history for this message
Victor Vargas (kamus) wrote :

Upstream said: Fixed in master and stable-2.0 branches. Thank you

Changed in banshee (Ubuntu):
importance: Undecided → Medium
status: New → Triaged
Changed in banshee:
status: Confirmed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package banshee - 2.0.0-1ubuntu1

---------------
banshee (2.0.0-1ubuntu1) natty; urgency=low

  * Merge from Debian Unstable, remaining changes:
    + Enable SoundMenu and Disable NotificationArea by default
    + Disable boo and karma extensions
    + Enable and recommnd u1ms and soundmenu extensions
    + Move desktop file for Meego UI to /usr/share/une/applications

banshee (2.0.0-1) unstable; urgency=low

  [ Chow Loong Jin ]
  * [ea911b3] New upstream release:
    + Enhancements:
      - Support Amazon Cloud Player browsing and downloading
      - 'Shuffle by' respects user-selected artist/album
      - Support LG Optimus S Android phone
      - Add DBus method to clear the play queue
    + Notable bugs fixed:
      - [AppleDevice] Sync dialog would be displayed forever
      - bgo#636448: AppleDevice: Fix music appearing in Videos in Banshee
      - Wrong mouse pointer on search box (LP: #723122)
  * [69aa1ac] Refresh 06_add-meego-desktop-file.patch

  [ Iain Lane ]
  * [eac3863] Add new patch to only bind to the loopback address for the DAAP proxy
    (LP: #753986)
 -- Chow Loong Jin <email address hidden> Wed, 06 Apr 2011 23:43:24 +0800

Changed in banshee (Ubuntu):
status: Triaged → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote : Please test proposed package

Hello Marc, or anyone else affected,

Accepted banshee into natty-proposed, the package will build now and be available in a few hours. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

Changed in banshee (Ubuntu Natty):
status: New → Fix Committed
tags: added: verification-needed
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

This was fixed in 2.0.0-1. Natty now has 2.0.0-2ubuntu2.

Changed in banshee (Ubuntu Natty):
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.