Bug 607293 (CVE-2010-2244)
Summary: | CVE-2010-2244 avahi: assertion failure after receiving a packet with corrupted checksum | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | medium | Docs Contact: | |||||
Priority: | medium | ||||||
Version: | unspecified | CC: | antillon.maurizio, lpoetter, tao, vdanen | ||||
Target Milestone: | --- | Keywords: | Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2012-11-29 15:14:48 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 607296, 607297, 609318, 609319, 833873 | ||||||
Bug Blocks: | |||||||
Attachments: |
|
Description
Jan Lieskovsky
2010-06-23 17:54:27 UTC
Created attachment 426335 [details]
Proposed patch by Ludwig Nussel (from [1])
Created avahi tracking bugs for this issue Affects: fedora-all [bug 607297] This has been assigned CVE-2010-2244. Lennart, have you had a chance to review the patch Ludwig provided to fix this yet? This issue affects the version of the avahi package, as shipped with Red Hat Enterprise Linux 5. This issue affects the versions of the avahi package, as shipped with Fedora releases of 12 and 13. Lennart, any reaction to c#5? Thanks, Jan. -- Jan iankko Lieskovsky / Red Hat Security Response Team Yes, the patch is good and merged upstream. I also did a new release upstream with this patch included, and uploaded that to Rawhide. avahi-0.6.25-7.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/avahi-0.6.25-7.fc13 avahi-0.6.25-7.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/avahi-0.6.25-7.fc12 commited and built for rhel 5.5.z and rhel 5.6 now. nvr are as follows: rhel5.5.z: avahi-0.6.16-9.el5.5 rhel5.6: avahi-0.6.16-9.el5 i uploaded a fix for rhel6 now too. avahi-0.6.25-7.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report. avahi-0.6.25-7.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report. This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2010:0528 https://rhn.redhat.com/errata/RHSA-2010-0528.html |