Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Avahi Denial of Service Vulnerability
Posted by Bill Keys
The vulnerability is caused due to an error when processing multicast
DNS (mDNS) data and can be exploited to terminate the application via an
UDP packet having a source port equal to zero.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2008-82 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2008-12-23
Severity: 2
Type: Local
------------------------------------------------------------------------
Summary
=======
A vulnerability has been reported in Avahi, which can be exploited by
malicious people to cause a DoS (Denial of Service).
Description
===========
The vulnerability is caused due to an error when processing multicast
DNS (mDNS) data and can be exploited to terminate the application via an
UDP packet having a source port equal to zero.
Affected packages:
Pardus 2008:
avahi, all before 0.6.23-12-7
Resolution
==========
There are update(s) for avahi. You can update them via Package Manager
or with a single command from console:
pisi up avahi
References
==========
* http://avahi.org/milestone/Avahi%200.6.24
* http://git.0pointer.de/?p=avahi.git;a=commitdiff;h=3093047f1aa36bed8a37fa79004bf0ee287929f4
* http://secunia.com/Advisories/33153
-----------------------------------------------------------------------
--
Pardus Security Team
http://security.pardus.org.tr
_______________________________________________
Pardus-security mailing list
Pardus-security@pardus.org.tr
http://liste.pardus.org.tr/mailman/listinfo/pardus-security