Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 133513
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sven Wegener <swegener@gentoo.org>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 133513 depends on: Show dependency tree
Bug 133513 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2006-05-16 10:36 0000
<net-dns/avahi-0.6.10 is vulnerable to the following:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2288
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2289

Didn't notice this as I bumped the ebuild to 0.6.10

------- Comment #1 From Stefan Cornelius (RETIRED) 2006-05-16 12:40:56 0000 -------
sparc and x86, please test and stable - thanks

Does this run as root? If not, this is probably only B3

------- Comment #2 From Gustavo Zacarias (RETIRED) 2006-05-16 12:46:07 0000 -------
sparc stable.

------- Comment #3 From Joshua Jackson 2006-05-16 21:51:11 0000 -------
all done on x86 as well ^.^

------- Comment #4 From Sune Kloppenborg Jeppesen 2006-05-16 22:30:11 0000 -------
Thx Joshua, but please don't close security bugs.

Time for GLSA decision. Impact is rather vague so I tend to vote NO.

------- Comment #5 From Raphael Marichez 2006-05-17 02:32:58 0000 -------
SA 20022 http://secunia.com/advisories/20022  shows details on the impact.

i think the buffer overflow comes from these lines of code :
http://0pointer.de/cgi-bin/viewcvs.cgi/trunk/avahi-core/rr.c?rev=1209&view=diff&r1=1209&r2=1208&p1=trunk/avahi-core/rr.c&p2=/trunk/avahi-core/rr.c

Remote exec of code is serious, but in this case, the official advisory says it
is hardly remotely exploitable.
http://0pointer.de/cgi-bin/viewcvs.cgi/*checkout*/trunk/docs/NEWS?root=avahi
"We do not consider either of them major security threats. "
"The buffer overflow is hard to exploit remotely, only local users can
become the 'avahi' user. In addition the user is trapped inside a
chroot() environment (at least on Linux). "

Concerning the DoS issue (exploitable from a local network only), it is also
possible to DoS avahi with inconsistent data. So the DoS issue is not very
serious as for me.

I vote NO.

------- Comment #6 From Stefan Cornelius (RETIRED) 2006-05-17 04:46:03 0000 -------
yet another no and closing. Of course, feel free to reopen if you disagree.

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug