It is currently Sun May 26, 2013 9:27 am

All times are UTC




Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: [Fixed]CVE-2008-5081 (avahi)
PostPosted: Mon Dec 15, 2008 2:16 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
Avahi 0.6.24 release wrote:
* A huge number of bug fixes, including a security relavant one (CVE-2008-5081, low risk)
* Add two new configuration directives "allow-interfaces" and "deny-interfaces" which can be used to make Avahi ignore certain network interfaces or only use certain network interfaces.
* A lot of translation updates


Secunia.com wrote:
A vulnerability has been reported in Avahi, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error when processing multicast DNS (mDNS) data and can be exploited to terminate the application via an UDP packet having a source port equal to zero.

The vulnerability is reported in versions prior to 0.6.24.


We currently have version 0.6.23 in SNAPSHOT

References:
http://secunia.com/Advisories/33153/
http://avahi.org/milestone/Avahi%200.6.24

!8!


Last edited by infwonder on Sat Jan 17, 2009 6:21 am, edited 1 time in total.

 Profile Send private message  
 
 Post subject: Re: [CVE-2008-5081] avahi < 0.6.24, local DoS
PostPosted: Mon Dec 15, 2008 3:42 pm 
Zenwalk Packager
Zenwalk Packager

Joined: Fri Mar 10, 2006 9:09 am
Posts: 2797
Location: Amsterdam
I already have a rebuild running on my 'current' system; i'll rebuild the 'snapshot' one this evening (i hope ;-) )

So: yes, i've seen it, and a rebuild/upgrade is on the way :-)

See also the test-request, but the package is here... Still being tested...


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-5081] avahi < 0.6.24, local DoS
PostPosted: Mon Dec 15, 2008 11:58 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
prfaasse wrote:
I already have a rebuild running on my 'current' system; i'll rebuild the 'snapshot' one this evening (i hope ;-) )

So: yes, i've seen it, and a rebuild/upgrade is on the way :-)

See also the test-request, but the package is here... Still being tested...



Thank you! \!D/


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-5081] avahi < 0.6.24, local DoS
PostPosted: Tue Dec 16, 2008 12:30 am 
Zenwalk Packager
Zenwalk Packager

Joined: Fri Mar 10, 2006 9:09 am
Posts: 2797
Location: Amsterdam
Did you test it? If so & ok, then we can 'go FiFo' quickly with this one \!D/


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-5081] avahi < 0.6.24, local DoS
PostPosted: Tue Dec 16, 2008 11:29 pm 
Master of the known universe
Master of the known universe
User avatar

Joined: Thu Mar 29, 2007 2:34 am
Posts: 1253
Location: Taiwan
prfaasse wrote:
Did you test it? If so & ok, then we can 'go FiFo' quickly with this one \!D/



D!! Sorry, what should I do in order to test it? I haven't use avahi before ... :-\


 Profile Send private message  
 
 Post subject: Re: [CVE-2008-5081] avahi < 0.6.24, local DoS
PostPosted: Wed Dec 17, 2008 12:04 am 
Zenwalk Packager
Zenwalk Packager

Joined: Fri Mar 10, 2006 9:09 am
Posts: 2797
Location: Amsterdam
The test-request (including test-instructions..) is here:

viewtopic.php?f=11&t=20136


 Profile Send private message  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC


 Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
 
cron