Bug 207930 - Update to avahi 0.6.13
Summary: Update to avahi 0.6.13
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: avahi
Version: 6
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Martin Bacovsky
QA Contact:
URL:
Whiteboard:
Keywords:
Depends On:
Blocks: FC7Target FC6Update
TreeView+ depends on / blocked
 
Reported: 2006-09-25 13:55 UTC by Matthias Clasen
Modified: 2007-11-30 22:11 UTC (History)
0 users

(edit)
Clone Of:
(edit)
Last Closed: 2006-11-29 15:20:11 UTC


Attachments (Terms of Use)

Description Matthias Clasen 2006-09-25 13:55:45 UTC
Contradicting myself here (I have said in the past that I don't like bugs for
new upstream versions...).

Comment 1 Martin Stransky 2006-10-02 12:24:36 UTC
It's quite late so we have to release it as an update...

Comment 2 Matthias Clasen 2006-10-03 04:09:33 UTC
Thats why I put this bug on the FC6Update tracker...

Comment 3 Todd Zullinger 2006-11-21 00:56:13 UTC
Forgive me if I'm missing a better place to put this.  I didn't see anything
more relevant searching BZ.

Avahi 0.6.15[1] was released 2006-11-06 and fixes CVE-2006-5461[2].  From the
CVE description:

"Avahi before 0.6.15 does not verify the sender identity of netlink messages to
ensure that they come from the kernel instead of another process, which allows
local users to spoof network changes to Avahi."

Perhaps that makes updating avahi a little more important?  There is a simple
patch[3] available from the Avahi home page that might be useful if updating
from 0.6.11 to 0.6.15 isn't feasible at the moment.

[1] http://avahi.org/download/avahi-0.6.15.tar.gz
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5461
[3] http://lathiat.net/avahi-0.6.15-netlink-source.diff

Comment 4 Fedora Update System 2006-11-28 21:08:41 UTC
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.

Comment 5 Fedora Update System 2006-12-11 16:08:36 UTC
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.