Bug 207930

Summary: Update to avahi 0.6.13
Product: [Fedora] Fedora Reporter: Matthias Clasen <mclasen>
Component: avahiAssignee: Martin Bacovsky <mbacovsk>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 6   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: avahi-0.6.15-1.fc6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-11-29 15:20:11 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 150225, 207681    

Description Matthias Clasen 2006-09-25 13:55:45 UTC
Contradicting myself here (I have said in the past that I don't like bugs for
new upstream versions...).

Comment 1 Martin Stransky 2006-10-02 12:24:36 UTC
It's quite late so we have to release it as an update...

Comment 2 Matthias Clasen 2006-10-03 04:09:33 UTC
Thats why I put this bug on the FC6Update tracker...

Comment 3 Todd Zullinger 2006-11-21 00:56:13 UTC
Forgive me if I'm missing a better place to put this.  I didn't see anything
more relevant searching BZ.

Avahi 0.6.15[1] was released 2006-11-06 and fixes CVE-2006-5461[2].  From the
CVE description:

"Avahi before 0.6.15 does not verify the sender identity of netlink messages to
ensure that they come from the kernel instead of another process, which allows
local users to spoof network changes to Avahi."

Perhaps that makes updating avahi a little more important?  There is a simple
patch[3] available from the Avahi home page that might be useful if updating
from 0.6.11 to 0.6.15 isn't feasible at the moment.

[1] http://avahi.org/download/avahi-0.6.15.tar.gz
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5461
[3] http://lathiat.net/avahi-0.6.15-netlink-source.diff

Comment 4 Fedora Update System 2006-11-28 21:08:41 UTC
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.

Comment 5 Fedora Update System 2006-12-11 16:08:36 UTC
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.