First published: Wed Jun 23 2010(Updated: )
Ludwig Nussel reported: [1] <a href="http://www.openwall.com/lists/oss-security/2010/06/23/4">http://www.openwall.com/lists/oss-security/2010/06/23/4</a> a deficiency in the way avahi daemon processed packets with corrupted checksum(s). A remote attacker on the same local are network (LAN) could send a DNS packet with broken checksum, that would cause avahi-daemon to exit unexpectedly due to a failed assertion check. Different vulnerability than <a href="https://access.redhat.com/security/cve/CVE-2008-5081">CVE-2008-5081</a>.
Affected Software | Affected Version | How to fix |
---|---|---|
Avahi AutoIP Daemon |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-607293 is high due to the potential for remote code execution from a local attacker.
To fix REDHAT-BUG-607293, ensure that you update the avahi-daemon package to its latest version as provided by your software vendor.
The vulnerability REDHAT-BUG-607293 affects systems running the Avahi avahi-daemon software.
REDHAT-BUG-607293 exploits a vulnerability in packet processing that can be triggered by corrupted checksums from remote attackers on the same LAN.
Yes, if exploited, REDHAT-BUG-607293 may allow an attacker to execute arbitrary code, potentially leading to data breaches.