Oval Definition:oval:org.mitre.oval:def:29261
Revision Date:2015-08-17Version:9
Title:RHSA-2009:0013 -- avahi security update (Moderate)
Description:Updated avahi packages that fix a security issue are now available for RedHat Enterprise Linux 5.This update has been rated as having moderate security impact by the RedHat Security Response Team.Avahi is an implementation of the DNS Service Discovery and Multicast DNSspecifications for Zeroconf Networking. It facilitates service discovery ona local network. Avahi and Avahi-aware applications allow you to plug yourcomputer into a network and, with no configuration, view other people tochat with, see printers to print to, and find shared files on other computers.Hugo Dias discovered a denial of service flaw in avahi-daemon. A remoteattacker on the same local area network (LAN) could send aspecially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemonto exit unexpectedly due to a failed assertion check. (CVE-2008-5081)All users are advised to upgrade to these updated packages, which contain abackported patch which resolves this issue. After installing the update,avahi-daemon will be restarted automatically.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2009:0013-CentOS 5
CVE-2008-5081
RHSA-2009:0013
Platform(s):CentOS Linux 5
Red Hat Enterprise Linux 5
Product(s):avahi
Definition Synopsis
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 5
  • OR The operating system installed on the system is CentOS Linux 5.x
  • AND Packages match section
  • avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-devel is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-glib is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1
  • OR avahi-tools is earlier than 0:0.6.16-1.el5_2.1
  • BACK