Login
Newsletter
Werbung

Sicherheit: Denial of Service in Avahi (Aktualisierung)
Aktuelle Meldungen Distributionen
Name: Denial of Service in Avahi (Aktualisierung)
ID: USN-5008-2
Distribution: Ubuntu
Plattformen: Ubuntu 14.04 ESM, Ubuntu 16.04 ESM
Datum: Mi, 7. Juli 2021, 23:12
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3468
Applikationen: Avahi
Update von: Zwei Probleme in Avahi

Originalnachricht


--===============0606504338503008317==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="J2SCkAp4GZ/dPZZf"
Content-Disposition: inline


--J2SCkAp4GZ/dPZZf
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

==========================================================================
Ubuntu Security Notice USN-5008-2
July 07, 2021

avahi vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Avahi could be made to denial of service if it received a specially crafted
input.

Software Description:
- avahi: Avahi IPv4LL network address configuration daemon

Details:

USN-5008-1 fixed a vulnerability in avahi. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.

Original advisory details:

Thomas Kremer discovered that Avahi incorrectly handled termination signals
on the Unix socket. A local attacker could possibly use this issue to cause
Avahi to hang, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
avahi-daemon 0.6.32~rc+dfsg-1ubuntu2.3+esm1
libavahi-core7 0.6.32~rc+dfsg-1ubuntu2.3+esm1

Ubuntu 14.04 ESM:
avahi-daemon 0.6.31-4ubuntu1.3+esm1
libavahi-core7 0.6.31-4ubuntu1.3+esm1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5008-2
https://ubuntu.com/security/notices/USN-5008-1
CVE-2021-3468

--J2SCkAp4GZ/dPZZf
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAmDmAeoACgkQRbznW4QL
H2lDgBAAr4MyvFBA5Y1bazuZK2h+v9gW5GSL7FdqpjPMxEyJ0DZ+2nKRNoTCbPBw
wysJSlO4bfyG3x70ufcUAe+3yymkm/y2yTY237GUAyCBY7fbKB37Q26xdKYR13Pl
bdxkYvju7Vf2KMZP5flTiiWfgtNRGhl0P6kgNx3+qHK10Lt9ZbOYfrJdJgVl/LjM
kClQHX04Q5RgvFbm1aku5FHMU1VG/aMNo22pSMaiqiIALRsCqwmC2yY3qNzar47a
+N4s/AkpM3B0TLIiu9C0Fo7410TLOrro0Y1Vpcs0WUv+/MYuFd0z5o+F+OTySwRK
kDGDgSvwRRVTT7Elbk6uGNU3JGXNEnHcKvbUoEFv+9gESGIatNgxxAQaHrJ01AMu
LpDCylKRE7sXFSBV2gpynVfF7W0/Bwc5kXT4iJmOBlLLqw6U1uBZMDNDQZOyVFgt
CMkvhvlM9/hwzwY8zuuqmprCi/mSicvFEvpjihm46qqxLTBgXcrYafbh1h3hktBU
2kU4SjAGYw/vyKWCkoBjSDWzl0oBB5Ad9umquIsBFKWON3eeD3BI/mr9lmIv6OGc
ZuVmYClzix5AcX6/IdnLHpwkJxN9HY6JXGpAG8PZCfkolaaCGw6o6TzrLn11qE+3
/iQ3TmOjr1sd1AaW7bH3s9R+A3VnHsrQylvNHSXc7UXanwCRjp8=
=D3Hk
-----END PGP SIGNATURE-----

--J2SCkAp4GZ/dPZZf--


--===============0606504338503008317==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung