Summary
Ubuntu Update for Linux kernel vulnerabilities USN-696-1
Solution
Please Install the Updated Packages.
Insight
Emanuele Aina discovered that Avahi did not properly validate it's input when processing data over D-Bus. A local attacker could send an empty TXT message via D-Bus and cause a denial of service (failed assertion). This issue only affected Ubuntu 6.06 LTS. (CVE-2007-3372)
Hugo Dias discovered that Avahi did not properly verify it's input when processing mDNS packets. A remote attacker could send a crafted mDNS packet and cause a denial of service (assertion failure). (CVE-2008-5081)
Affected
avahi vulnerabilities on Ubuntu 6.06 LTS ,
Ubuntu 7.10 ,
Ubuntu 8.04 LTS ,
Ubuntu 8.10
References
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2007-3372, CVE-2008-5081 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities