Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 260971
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Robert Buchholz <rbu@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
net-dns:avahi-0.6.24-r2:20090307-102952.log net-dns:avahi-0.6.24-r2:20090307-102952.log text/plain Markus Meier 2009-03-07 10:33 0000 16.77 KB Details
config.log config.log text/plain Markus Meier 2009-03-07 10:34 0000 148.40 KB Details
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 260971 depends on: Show dependency tree
Bug 260971 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2009-03-02 17:28 0000
Rob Leslie reported that the avahi daemon creates packet storm on legacy
unicast traffic, see URL for details.

------- Comment #1 From Robert Buchholz 2009-03-04 17:08:42 0000 -------
CVE-2009-0758 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0758):
  The originates_from_local_legacy_unicast_socket function in
  avahi-core/server.c in avahi-daemon 0.6.23 does not account for the
  network byte order of a port number when processing incoming
  multicast packets, which allows remote attackers to cause a denial of
  service (network bandwidth and CPU consumption) via a crafted legacy
  unicast mDNS query packet that triggers a multicast packet storm.

------- Comment #2 From Sven Wegener 2009-03-06 14:45:33 0000 -------
I've applied the patch to net-dns/avahi-0.6.24-r1

------- Comment #3 From Robert Buchholz 2009-03-06 18:12:31 0000 -------
Arches, please test and mark stable:
=net-dns/avahi-0.6.24-r1
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"

------- Comment #4 From Sven Wegener 2009-03-06 23:31:00 0000 -------
Please mark avahi-0.6.24-r2 stable, it contains a fix for libtool-2.

------- Comment #5 From Markus Meier 2009-03-07 10:33:52 0000 -------
Created an attachment (id=184208) [details]
net-dns:avahi-0.6.24-r2:20090307-102952.log

seems to have troubles with libtool-1.5.26 here on amd64/x86.

------- Comment #6 From Markus Meier 2009-03-07 10:34:24 0000 -------
Created an attachment (id=184210) [details]
config.log

------- Comment #7 From Jeroen Roovers 2009-03-07 18:15:37 0000 -------
Stable for HPPA.

------- Comment #8 From Tobias Klausmann 2009-03-08 15:59:22 0000 -------
Stable on alpha. 

------- Comment #9 From Brent Baude 2009-03-11 13:36:27 0000 -------
ppc64 done

------- Comment #10 From Raúl Porcel 2009-03-16 13:04:35 0000 -------
(In reply to comment #5)
> Created an attachment (id=184208) [edit] [details]
> net-dns:avahi-0.6.24-r2:20090307-102952.log
> 
> seems to have troubles with libtool-1.5.26 here on amd64/x86.
> 

Same here on x86, yet on alpha doesn't give any issues with the same USE-flags
:/

------- Comment #11 From Brent Baude 2009-03-19 13:10:02 0000 -------
ppc done

------- Comment #12 From Diego E. 'Flameeyes' Pettenò 2009-03-23 17:06:44 0000 -------
That log is not libtool, it's intltool. The ebuild lacks a dependency over a
newer version of intltool.

The avahi versions released up to now use libtool 1.5 by default.

------- Comment #13 From Raúl Porcel 2009-03-25 19:05:36 0000 -------
(In reply to comment #12)
> That log is not libtool, it's intltool. The ebuild lacks a dependency over a
> newer version of intltool.
> 
> The avahi versions released up to now use libtool 1.5 by default.
> 

Indeed, with stable intltool on x86 it works now...probably this bug should
depend on the gnome stabilization.

------- Comment #14 From Raúl Porcel 2009-03-27 11:26:59 0000 -------
arm/ia64/s390/sh/sparc/x86 stable

------- Comment #15 From Markus Meier 2009-03-29 21:28:12 0000 -------
amd64 stable, all arches done.

------- Comment #16 From Robert Buchholz 2009-04-08 22:48:24 0000 -------
GLSA 200904-10

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug