Pardus alert 2010-97 (avahi)
| From: | Eren Turkay <eren@pardus.org.tr> | |
| To: | pardus-security@pardus.org.tr | |
| Subject: | [Pardus-security] [PLSA 2010-97] Avahi: Denial of Service | |
| Date: | Thu, 8 Jul 2010 13:54:22 +0300 (EEST) | |
| Message-ID: | <20100708105422.22EF3A7AB3D@lider.pardus.org.tr> |
------------------------------------------------------------------------ Pardus Linux Security Advisory 2010-97 security@pardus.org.tr ------------------------------------------------------------------------ Date: 2010-07-08 Severity: 3 Type: Local ------------------------------------------------------------------------ Summary ======= A denial of service vulnerability has been fixed in Avahi, which can be used by malicious people to crash the server. Description =========== CVE-2010-2244: Avahi crashes if it receives a bad packet (broken checksum) immediately followed by a good packet. In that case FIONREAD returns zero size for the bad packet. avahi doesn't consider that an error and calls recvmsg() which succeeds and returns the good packet which has a non-zero length of course. This discrepancy causes an assert() to fail and avahi terminates. Affected packages: Pardus 2009: avahi, all before 0.6.25-16-4 Resolution ========== There are update(s) for avahi. You can update them via Package Manager or with a single command from console: pisi up avahi References ========== * http://bugs.pardus.org.tr/show_bug.cgi?id=13641 ------------------------------------------------------------------------ _______________________________________________ Pardus-security mailing list Pardus-security@pardus.org.tr http://liste.pardus.org.tr/mailman/listinfo/pardus-security
