CVE-2008-5081 at MITRE
Details
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.
Novell Bugzilla entry:
459007
SUSE Security Advisories:
| Product(s) | Fixed package version(s) | References |
| openSUSE 10.3 | avahi >= 0.6.20-40.2 avahi-32bit >= 0.6.20-40.2 avahi-64bit >= 0.6.20-40.2 avahi-compat-howl >= 0.6.20-40.2 avahi-compat-howl-devel >= 0.6.20-40.2 avahi-compat-mDNSResponder >= 0.6.20-40.2 avahi-compat-mDNSResponder-32bit >= 0.6.20-40.2 avahi-compat-mDNSResponder-64bit >= 0.6.20-40.2 avahi-compat-mDNSResponder-devel >= 0.6.20-40.2 avahi-devel >= 0.6.20-40.2 avahi-glib >= 0.6.20-40.2 avahi-glib-32bit >= 0.6.20-40.2 avahi-glib-64bit >= 0.6.20-40.2 avahi-python >= 0.6.20-40.2 avahi-qt3 >= 0.6.20-40.2 avahi-qt4 >= 0.6.20-40.2
| ZYPP Patch Nr: 5882 SAT Patch Nr: 384 |
| openSUSE 11.0 | avahi-debuginfo >= 0.6.22-68.2 avahi-debugsource >= 0.6.22-68.2 avahi-qt4-debuginfo >= 0.6.22-8.2 avahi-qt4-debugsource >= 0.6.22-8.2
| ZYPP Patch Nr: 5882 SAT Patch Nr: 384 |
| openSUSE 11.0 | avahi >= 0.6.22-68.2 avahi-compat-howl-devel >= 0.6.22-68.2 avahi-compat-mDNSResponder-devel >= 0.6.22-68.2 avahi-utils >= 0.6.22-68.2 avahi-utils-gtk >= 0.6.22-68.2 libavahi-client3 >= 0.6.22-68.2 libavahi-client3-32bit >= 0.6.22-68.2 libavahi-client3-64bit >= 0.6.22-68.2 libavahi-common3 >= 0.6.22-68.2 libavahi-common3-32bit >= 0.6.22-68.2 libavahi-common3-64bit >= 0.6.22-68.2 libavahi-core5 >= 0.6.22-68.2 libavahi-devel >= 0.6.22-68.2 libavahi-glib-devel >= 0.6.22-68.2 libavahi-glib1 >= 0.6.22-68.2 libavahi-glib1-32bit >= 0.6.22-68.2 libavahi-glib1-64bit >= 0.6.22-68.2 libavahi-gobject-devel >= 0.6.22-68.2 libavahi-gobject0 >= 0.6.22-68.2 libavahi-ui0 >= 0.6.22-68.2 libdns_sd >= 0.6.22-68.2 libdns_sd-32bit >= 0.6.22-68.2 libdns_sd-64bit >= 0.6.22-68.2 libhowl0 >= 0.6.22-68.2 python-avahi >= 0.6.22-68.2
| ZYPP Patch Nr: 5882 SAT Patch Nr: 384 |
| openSUSE 11.1 | avahi >= 0.6.23-9.1 avahi-compat-howl-devel >= 0.6.23-9.1 avahi-compat-mDNSResponder-devel >= 0.6.23-9.1 avahi-debuginfo >= 0.6.23-9.1 avahi-debugsource >= 0.6.23-9.1 avahi-qt4-debuginfo >= 0.6.23-9.1 avahi-qt4-debugsource >= 0.6.23-9.1 avahi-utils >= 0.6.23-9.1 libavahi-client3 >= 0.6.23-9.1 libavahi-client3-32bit >= 0.6.23-9.1 libavahi-common3 >= 0.6.23-9.1 libavahi-common3-32bit >= 0.6.23-9.1 libavahi-core5 >= 0.6.23-9.1 libavahi-devel >= 0.6.23-9.1 libavahi-glib-devel >= 0.6.23-9.1 libavahi-glib1 >= 0.6.23-9.1 libavahi-glib1-32bit >= 0.6.23-9.1 libavahi-gobject-devel >= 0.6.23-9.1 libavahi-gobject0 >= 0.6.23-9.1 libavahi-ui0 >= 0.6.23-9.1 libdns_sd >= 0.6.23-9.1 libdns_sd-32bit >= 0.6.23-9.1 libhowl0 >= 0.6.23-9.1 python-avahi >= 0.6.23-9.1
| ZYPP Patch Nr: 5882 SAT Patch Nr: 384 |
| openSUSE 11.1 | avahi >= 0.6.23-9.1 avahi-compat-howl-devel >= 0.6.23-9.1 avahi-compat-mDNSResponder-devel >= 0.6.23-9.1 avahi-utils >= 0.6.23-9.1 libavahi-client3 >= 0.6.23-9.1 libavahi-client3-32bit >= 0.6.23-9.1 libavahi-client3-64bit >= 0.6.23-9.2 libavahi-common3 >= 0.6.23-9.1 libavahi-common3-32bit >= 0.6.23-9.1 libavahi-common3-64bit >= 0.6.23-9.2 libavahi-core5 >= 0.6.23-9.1 libavahi-devel >= 0.6.23-9.1 libavahi-glib-devel >= 0.6.23-9.1 libavahi-glib1 >= 0.6.23-9.1 libavahi-glib1-32bit >= 0.6.23-9.1 libavahi-glib1-64bit >= 0.6.23-9.1 libavahi-gobject-devel >= 0.6.23-9.1 libavahi-gobject0 >= 0.6.23-9.1 libavahi-ui0 >= 0.6.23-9.1 libdns_sd >= 0.6.23-9.1 libdns_sd-32bit >= 0.6.23-9.1 libdns_sd-64bit >= 0.6.23-9.2 libhowl0 >= 0.6.23-9.1 python-avahi >= 0.6.23-9.1
| ZYPP Patch Nr: 5882 SAT Patch Nr: 384 |
SUSE Linux Enterprise Desktop 10 SP2 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP2 for x86 | avahi >= 0.6.5-29.19 avahi-glib >= 0.6.5-29.19
| sles10-sp2-sdk. x86-64 sles10-sp2-sdk. x86 sles10-sp2-sdk. ppc sled10-sp2. x86-64 sles10-sp2-sdk. ia64 sles10-sp2-sdk. s390x sled10-sp2. x86 ZYPP Patch Nr: 5870 |
SLE SDK 10 SP2 for IBM iSeries and IBM pSeries SLE SDK 10 SP2 for IBM zSeries SLE SDK 10 SP2 for IPF SLE SDK 10 SP2 for X86-64 SLE SDK 10 SP2 for x86 | avahi >= 0.6.5-29.19 avahi-devel >= 0.6.5-29.19 avahi-glib >= 0.6.5-29.19
| sles10-sp2-sdk. x86-64 sles10-sp2-sdk. x86 sles10-sp2-sdk. ppc sled10-sp2. x86-64 sles10-sp2-sdk. ia64 sles10-sp2-sdk. s390x sled10-sp2. x86 ZYPP Patch Nr: 5870 |