Update RELEASENOTES.md
This commit is contained in:
@@ -1,3 +1,10 @@
|
||||
Version 3.2d13
|
||||
====
|
||||
**Security Update**
|
||||
|
||||
* The version of `tinysvcmdns` bundled in Shairport Sync has a buffer overflow bug: *"An exploitable heap overflow vulnerability exists in the tinysvcmdns library version 2016-07-18. A specially crafted packet can make the library overwrite an arbitrary amount of data on the heap with attacker controlled values. An attacker needs send a dns packet to trigger this vulnerability."* The vulnerability is addressed by additional checking on packet sizes. See also [Vulnerability in tinysvcmdns](https://bugs.launchpad.net/ubuntu/+source/shairport-sync/+bug/1729668). CVE-2017-12087.
|
||||
Thanks and [Chris Boot](https://github.com/bootc) for fixing this bug.
|
||||
|
||||
Version 3.2d12
|
||||
====
|
||||
Experimenting with an [MPRIS](https://specifications.freedesktop.org/mpris-spec/latest/)-compatible D-Bus interface. A very small number of features have a tentative implementation. As with the Shairport Sync D-Bus interface, please note that the implementation is likely to change greatly or be removed at any time.
|
||||
|
||||
Reference in New Issue
Block a user