First published: Thu Jan 31 2019(Updated: )
Chad Seaman discovered that Avahi incorrectly handled certain messages. An attacker could possibly use this issue to cause a denial of service. (CVE-2017-6519, CVE-2018-1000845)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/avahi-daemon | <0.7-4ubuntu2.1 | 0.7-4ubuntu2.1 |
Ubuntu OpenSSH Client | =18.10 | |
All of | ||
ubuntu/libavahi-core7 | <0.7-4ubuntu2.1 | 0.7-4ubuntu2.1 |
Ubuntu OpenSSH Client | =18.10 | |
All of | ||
ubuntu/avahi-daemon | <0.7-3.1ubuntu1.2 | 0.7-3.1ubuntu1.2 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/libavahi-core7 | <0.7-3.1ubuntu1.2 | 0.7-3.1ubuntu1.2 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/avahi-daemon | <0.6.32~rc+dfsg-1ubuntu2.3 | 0.6.32~rc+dfsg-1ubuntu2.3 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/libavahi-core7 | <0.6.32~rc+dfsg-1ubuntu2.3 | 0.6.32~rc+dfsg-1ubuntu2.3 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/avahi-daemon | <0.6.31-4ubuntu1.3 | 0.6.31-4ubuntu1.3 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/libavahi-core7 | <0.6.31-4ubuntu1.3 | 0.6.31-4ubuntu1.3 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-3876-1 is classified as a denial of service vulnerability.
To fix USN-3876-1, update the affected packages avahi-daemon or libavahi-core7 to the recommended versions based on your Ubuntu release.
USN-3876-1 affects Ubuntu versions 14.04, 16.04, 18.04, and 18.10.
The vulnerable packages in USN-3876-1 include avahi-daemon and libavahi-core7.
USN-3876-1 was discovered by Chad Seaman.