Red Hat Bugzilla – Bug 207930
Update to avahi 0.6.13
Last modified: 2007-11-30 17:11:44 EST
Contradicting myself here (I have said in the past that I don't like bugs for
new upstream versions...).
It's quite late so we have to release it as an update...
Thats why I put this bug on the FC6Update tracker...
Forgive me if I'm missing a better place to put this. I didn't see anything
more relevant searching BZ.
Avahi 0.6.15 was released 2006-11-06 and fixes CVE-2006-5461. From the
"Avahi before 0.6.15 does not verify the sender identity of netlink messages to
ensure that they come from the kernel instead of another process, which allows
local users to spoof network changes to Avahi."
Perhaps that makes updating avahi a little more important? There is a simple
patch available from the Avahi home page that might be useful if updating
from 0.6.11 to 0.6.15 isn't feasible at the moment.
avahi-0.6.15-1.fc6 has been pushed for fc6, which should resolve this issue. If these problems are still present in this version, then please make note of it in this bug report.