In the latest development version of commons, we get an alert at admin/reports/status that:

"Your getID3 library is insecure! The demos distributed with getID3 contains code which creates a huge security hole. Remove the demos directory (......profiles/drupal_commons/libraries/getid3/demos) from beneath Drupal's directory.""

One question is how to package with Drush make and not include this demos directory. I don't think Drush make can *remove* a downloaded directory from within a library and I don't think that getID3 is distributed without that directory. Hosting our own copy on GitHub seems like an easy, if awkward option.

It also seems like its time to update to getID3 1.9.

Comments

ezra-g’s picture

Actually, looks like getID3 is GPL 2. Maybe this means we can include it in the Commons repo?

ezra-g’s picture

ezra-g’s picture

Title: getid3 library demo directory included » Remove id3 demo directory
Status: Active » Needs review
StatusFileSize
new282.32 KB

Attached is a patch that removes this unwanted directory.

The 1336886-remove-id3-demos-dir branch of Commons modifies drupal_commons.make to use this patch when building Commons.

ezra-g’s picture

StatusFileSize
new300.95 KB

Here's an updated patch for getid3 1.9.1

laurentc’s picture

Cool. The patch is good.

ezra-g’s picture

Category: bug » task
Status: Needs review » Fixed

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.

janusman’s picture

Version: » 6.x-2.x-dev
StatusFileSize
new301.9 KB

Just for reference, adding this patch that removes the demos directory from a newer version of getid3 (1.9.3)

Anonymous’s picture

StatusFileSize
new312.1 KB

Here is a patch for getid3 1.9.5.

Anonymous’s picture

Issue summary: View changes
StatusFileSize
new312.76 KB

Here is a patch to remove demos in 1.9.7.

jhedstrom’s picture

StatusFileSize
new313.6 KB

This patch is actually used in a drush make test, so I needed to reroll it for 1.9.8. Sorry for the noise.