RHSA-2009:0013: Moderate: avahi security update
Avahi is an implementation of the DNS Service Discovery and Multicast DNSspecifications for Zeroconf Networking. It facilitates service discovery ona local network. Avahi and Avahi-aware applications allow you to plug yourcomputer into a network and, with no configuration, view other people tochat with, see printers to print to, and find shared files on other computers.Hugo Dias discovered a denial of service flaw in avahi-daemon. A remoteattacker on the same local area network (LAN) could send aspecially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemonto exit unexpectedly due to a failed assertion check. (CVE-2008-5081)All users are advised to upgrade to these updated packages, which contain abackported patch which resolves this issue. After installing the update,avahi-daemon will be restarted automatically.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:0013?
The severity of RHSA-2009:0013 is classified as moderate.
How do I fix RHSA-2009:0013?
You can fix RHSA-2009:0013 by updating the Avahi packages to version 0.6.16-1.el5_2.1.
What software is affected by RHSA-2009:0013?
RHSA-2009:0013 affects the Avahi package along with its related packages including avahi-compat-howl and avahi-devel.
When was the vulnerability RHSA-2009:0013 announced?
The vulnerability RHSA-2009:0013 was announced on January 13, 2009.
Is there a workaround for RHSA-2009:0013?
There are no specific workarounds for RHSA-2009:0013; the recommended action is to apply the security update.