Bug 207930 - Update to avahi 0.6.13
Update to avahi 0.6.13
Status: CLOSED CURRENTRELEASE
Product: Fedora
Classification: Fedora
Component: avahi (Show other bugs)
6
All Linux
medium Severity medium
: ---
: ---
Assigned To: Martin Bacovsky
:
Depends On:
Blocks: FC7Target FC6Update
  Show dependency treegraph
 
Reported: 2006-09-25 09:55 EDT by Matthias Clasen
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version: avahi-0.6.15-1.fc6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-11-29 10:20:11 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Matthias Clasen 2006-09-25 09:55:45 EDT
Contradicting myself here (I have said in the past that I don't like bugs for
new upstream versions...).
Comment 1 Martin Stransky 2006-10-02 08:24:36 EDT
It's quite late so we have to release it as an update...
Comment 2 Matthias Clasen 2006-10-03 00:09:33 EDT
Thats why I put this bug on the FC6Update tracker...
Comment 3 Todd Zullinger 2006-11-20 19:56:13 EST
Forgive me if I'm missing a better place to put this.  I didn't see anything
more relevant searching BZ.

Avahi 0.6.15[1] was released 2006-11-06 and fixes CVE-2006-5461[2].  From the
CVE description:

"Avahi before 0.6.15 does not verify the sender identity of netlink messages to
ensure that they come from the kernel instead of another process, which allows
local users to spoof network changes to Avahi."

Perhaps that makes updating avahi a little more important?  There is a simple
patch[3] available from the Avahi home page that might be useful if updating
from 0.6.11 to 0.6.15 isn't feasible at the moment.

[1] http://avahi.org/download/avahi-0.6.15.tar.gz
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5461
[3] http://lathiat.net/avahi-0.6.15-netlink-source.diff
Comment 4 Fedora Update System 2006-11-28 16:08:41 EST
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.
Comment 5 Fedora Update System 2006-12-11 11:08:36 EST
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.