LWN.net Logo

Fedora alert FEDORA-2006-1339 (avahi)

From:  "Martin Bacovsky" <mbacovsk@redhat.com>
To:  fedora-package-announce@redhat.com
Subject:  [SECURITY] Fedora Core 5 Update: avahi-0.6.11-2.fc5
Date:  Tue, 28 Nov 2006 16:08:35 -0500

--------------------------------------------------------------------- Fedora Update Notification FEDORA-2006-1339 2006-11-28 --------------------------------------------------------------------- Product : Fedora Core 5 Name : avahi Version : 0.6.11 Release : 2.fc5 Summary : Local network service discovery Description : Avahi is a system which facilitates service discovery on a local network -- this means that you can plug your laptop or computer into a network and instantly be able to view other people who you can chat with, find printers to print to or find files being shared. This kind of technology is already found in MacOS X (branded 'Rendezvous', 'Bonjour' and sometimes 'ZeroConf') and is very convenient. --------------------------------------------------------------------- Update Information: Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi. avahi-0.6.11-2.fc5 has applied patch which should resolve this issue. --------------------------------------------------------------------- * Tue Nov 28 2006 Martin Bacovsky <mbacovsk@redhat.com> - 0.6.11-2.fc5 - fix bug #216655 - CVE-2006-5461 - avahi did not verify the sender identity of netlink messages * Mon Jul 17 2006 Jason Vas Dias <jvdias@redhat.com> - 0.6.11-1 - Upgrade to upstream version 0.6.11 - fix bug 195674: set 'use-ipv6=yes' in avahi-daemon.conf - fix bug 197414: avahi-compat-howl and avahi-compat-dns-sd symlinks - fix bug 198282: avahi-compat-{howl-devel,dns-sd-devel} Requires: * Tue Jun 13 2006 Jason Vas Dias <jvdias@redhat.com> - 0.6.10-3 - rebuild for broken mono deps * Tue Jun 6 2006 Jason Vas Dias <jvdias@redhat.com> - 0.6.10-2 - fix bug 194203: fix permissions on /var/run/avahi-daemon * Tue May 30 2006 Jason Vas Dias <jvdias@redhat.com> - 0.6.10-1 - Upgrade to upstream version 0.6.10 - fix bug 192080: split avahi-compat-libdns_sd into separate package (same goes for avahi-compat-howl) --------------------------------------------------------------------- This update can be downloaded from: http://download.fedora.redhat.com/pub/fedora/linux/core/u... 32e2c4234b36bc666452f7da2e535ce584c9a5f2 SRPMS/avahi-0.6.11-2.fc5.src.rpm 32e2c4234b36bc666452f7da2e535ce584c9a5f2 noarch/avahi-0.6.11-2.fc5.src.rpm e7878885bdfdac88465e8d75cc944edfc5c050ac ppc/avahi-tools-0.6.11-2.fc5.ppc.rpm 8b85236b8a0c131d808b129b46eab3d6103aa454 ppc/avahi-sharp-0.6.11-2.fc5.ppc.rpm 48f0653952fab3f5a8838f259561dd5b4fe96644 ppc/avahi-glib-0.6.11-2.fc5.ppc.rpm 8b432ebf70bcf6e262847b4af4e62354f91a0398 ppc/avahi-qt3-0.6.11-2.fc5.ppc.rpm e606766364bff31efd5605909206d8f37db7fd7b ppc/avahi-compat-libdns_sd-devel-0.6.11-2.fc5.ppc.rpm 126381e1619178e3c81d33183f43d5a16f5f10d1 ppc/avahi-compat-howl-0.6.11-2.fc5.ppc.rpm d10abaafae20b30e33e5f67a437e742f04e2d054 ppc/avahi-compat-howl-devel-0.6.11-2.fc5.ppc.rpm 7002d6d37cc939d33b9f5db23b7f3166dff11ffe ppc/avahi-glib-devel-0.6.11-2.fc5.ppc.rpm 9853cc873a2419adc8fb7942ac82a0abe0dee325 ppc/avahi-compat-libdns_sd-0.6.11-2.fc5.ppc.rpm c04558487aaa2d8c10fb5111e04618663359c631 ppc/debug/avahi-debuginfo-0.6.11-2.fc5.ppc.rpm 1b90058cb273400be88e188443837094dba72739 ppc/avahi-0.6.11-2.fc5.ppc.rpm 789f280325469aa7a9ae204bc626c7e540d23a89 ppc/avahi-devel-0.6.11-2.fc5.ppc.rpm 8cf14aa4277f5a7d319c9b16a0b3c04d3c8e2d2e ppc/avahi-qt3-devel-0.6.11-2.fc5.ppc.rpm b8ec59cfdba1a782a4756cc8eaabfdbb0141463d x86_64/avahi-0.6.11-2.fc5.x86_64.rpm 5db55bf5e5f74747e1f270e1d8f5db94bd792b1e x86_64/avahi-qt3-0.6.11-2.fc5.x86_64.rpm 1e8541f9200f549242f75829245f12e373b6657e x86_64/avahi-tools-0.6.11-2.fc5.x86_64.rpm 619d02b9858b6919de73d1f282def04a0206f1f4 x86_64/avahi-compat-libdns_sd-devel-0.6.11-2.fc5.x86_64.rpm b238a4ad792213c6bef937ab7e2affb4b01228cc x86_64/avahi-glib-devel-0.6.11-2.fc5.x86_64.rpm 88a19292dd0aabe70d847e9e5696064a23496030 x86_64/avahi-sharp-0.6.11-2.fc5.x86_64.rpm acb1349ebfc2c0be8f70879663e6c7ba51474765 x86_64/avahi-compat-libdns_sd-0.6.11-2.fc5.x86_64.rpm 295b97f46085e061c15eba646086dabdfc083865 x86_64/avahi-compat-howl-devel-0.6.11-2.fc5.x86_64.rpm 1cf7a7b590a58594fa902df044097eb3aa40489b x86_64/avahi-devel-0.6.11-2.fc5.x86_64.rpm 7106de09822d3c476462d817f75785792be04796 x86_64/avahi-qt3-devel-0.6.11-2.fc5.x86_64.rpm 7184f38c4860a9fb0356814c82c2627e39b4fdac x86_64/avahi-compat-howl-0.6.11-2.fc5.x86_64.rpm 87a14203c10a0b90ba21af488ee23a7ca7d6cf19 x86_64/debug/avahi-debuginfo-0.6.11-2.fc5.x86_64.rpm 34cbbee318c39fac97e5d2d44f714b80d031ef59 x86_64/avahi-glib-0.6.11-2.fc5.x86_64.rpm fe1ead4771f1c3530b7b209aaff9f9515d2832f1 i386/avahi-0.6.11-2.fc5.i386.rpm 25cf794c7369537a2090feb43e395e8a6dffd31d i386/avahi-devel-0.6.11-2.fc5.i386.rpm 53d4c61fd5fcab1b83c865482cecde7f6315d26c i386/avahi-sharp-0.6.11-2.fc5.i386.rpm 2f6bad6cbae3395a5e87e44798febe668849d2b1 i386/debug/avahi-debuginfo-0.6.11-2.fc5.i386.rpm a3f946078cfcbe5e16202a9833886359d6258335 i386/avahi-glib-0.6.11-2.fc5.i386.rpm ef57058a0087ead570cf032e03863b8513888478 i386/avahi-qt3-0.6.11-2.fc5.i386.rpm d4e6563ac4e94b387fa77c10f5e897c93b8997a5 i386/avahi-glib-devel-0.6.11-2.fc5.i386.rpm 8f341c7be89010bc7c7b2cf31bd9264fd73a9bf1 i386/avahi-compat-libdns_sd-0.6.11-2.fc5.i386.rpm 2f7b976637f72dd0c6fd7c32754a51cb5b9d67d4 i386/avahi-tools-0.6.11-2.fc5.i386.rpm 7b8181da5b4570821566e94c499b6aa0476190fc i386/avahi-compat-howl-devel-0.6.11-2.fc5.i386.rpm f98be70953469c75a1b21c6aed64def14fd3ae72 i386/avahi-compat-libdns_sd-devel-0.6.11-2.fc5.i386.rpm e58c1f77b6be9525b2fccfbfe003efca1463ec3b i386/avahi-compat-howl-0.6.11-2.fc5.i386.rpm 604cd0d660ce8bb1c0a5ab3dfe6a0478069fe7f1 i386/avahi-qt3-devel-0.6.11-2.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at http://fedora.redhat.com/docs/yum/. --------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds