Bug 207930
Summary: | Update to avahi 0.6.13 | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Matthias Clasen <mclasen> |
Component: | avahi | Assignee: | Martin Bacovsky <mbacovsk> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 6 | ||
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | avahi-0.6.15-1.fc6 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2006-11-29 15:20:11 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 150225, 207681 |
Description
Matthias Clasen
2006-09-25 13:55:45 UTC
It's quite late so we have to release it as an update... Thats why I put this bug on the FC6Update tracker... Forgive me if I'm missing a better place to put this. I didn't see anything more relevant searching BZ. Avahi 0.6.15[1] was released 2006-11-06 and fixes CVE-2006-5461[2]. From the CVE description: "Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi." Perhaps that makes updating avahi a little more important? There is a simple patch[3] available from the Avahi home page that might be useful if updating from 0.6.11 to 0.6.15 isn't feasible at the moment. [1] http://avahi.org/download/avahi-0.6.15.tar.gz [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5461 [3] http://lathiat.net/avahi-0.6.15-netlink-source.diff avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report. avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report. |