USN-992-1: Avahi vulnerabilities
29 September 2010
Releases
Packages
- avahi -
Details
It was discovered that Avahi incorrectly handled certain mDNS query packets
when the reflector feature is enabled, which is not the default
configuration on Ubuntu. A remote attacker could send crafted mDNS queries
and perform a denial of service on the server and on the network. This
issue only affected Ubuntu 8.04 LTS and 9.04. (CVE-2009-0758)
It was discovered that Avahi incorrectly handled mDNS packets with
corrupted checksums. A remote attacker could send crafted mDNS packets and
cause Avahi to crash, resulting in a denial of service. (CVE-2010-2244)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 8.04
Ubuntu 10.04
After a standard system update you need to reboot your computer to make
all the necessary changes.