Bug 154322 - net-dns/avahi netlink issue (CVE-2006-5461)
Bug#: 154322 Product:  Gentoo Security Version: unspecified Platform: All
OS/Version: Linux Status: RESOLVED Severity: normal Priority: P2
Resolution: FIXED Assigned To: security@gentoo.org Reported By: jaervosz@gentoo.org
Component: Vulnerabilities
URL:  http://avahi.org/milestone/Avahi 0.6.15
Summary: net-dns/avahi netlink issue (CVE-2006-5461)
Keywords:  
Status Whiteboard: B3? [glsa]
Opened: 2006-11-07 00:32 0000
Description:   Opened: 2006-11-07 00:32 0000
Check that netlink messages actually originate from the kernel and not another
process.

------- Comment #1 From Matthias Geerdsen 2006-11-09 07:01:34 0000 -------
*** Bug 154563 has been marked as a duplicate of this bug. ***

------- Comment #2 From Matthias Geerdsen 2006-11-09 07:04:18 0000 -------
arches, pls test avahi-0.6.15 and mark stable if possible

------- Comment #3 From Tobias Scherbaum 2006-11-09 07:40:29 0000 -------
ppc stable, adding arches *cough*

------- Comment #4 From Gustavo Zacarias (RETIRED) 2006-11-09 10:12:47 0000 -------
sparc stable.

------- Comment #5 From Christian Faulhammer 2006-11-10 01:20:52 0000 -------
Broadcasting on x86

------- Comment #6 From Daniel Gryniewicz 2006-11-10 10:16:18 0000 -------
amd64 done.

------- Comment #7 From René Nussbaumer 2006-11-13 12:12:12 0000 -------
stable on hppa

------- Comment #8 From Bryan Østergaard (RETIRED) 2006-11-14 09:33:44 0000 -------
Stable on Alpha.

------- Comment #9 From Markus Rothe 2006-11-15 05:22:20 0000 -------
ppc64 stable. sorry for being late.

------- Comment #10 From Matthias Geerdsen 2006-11-15 12:52:28 0000 -------
security please vote on GLSA publication

------- Comment #11 From Sune Kloppenborg Jeppesen 2006-11-15 21:24:31 0000 -------
I tend to vote YES.

------- Comment #12 From Matthias Geerdsen 2006-11-16 03:17:26 0000 -------
so do I

one full vote still missing

------- Comment #13 From Wolf Giesen (RETIRED) 2006-11-16 03:38:12 0000 -------
Take this, then .-)

------- Comment #14 From Sune Kloppenborg Jeppesen 2006-11-20 12:59:15 0000 -------
GLSA 200611-13