Upstream information

CVE-2008-5081 at MITRE

Description

The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 5
Vector AV:N/AC:L/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial
SUSE Bugzilla entries: 459007 [RESOLVED / FIXED], 646961 [RESOLVED / DUPLICATE]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP1
  • avahi >= 0.6.23-11.19.22
  • avahi-lang >= 0.6.23-11.19.22
  • avahi-utils >= 0.6.23-11.19.22
  • libavahi-client3 >= 0.6.23-11.19.22
  • libavahi-client3-32bit >= 0.6.23-11.19.22
  • libavahi-client3-x86 >= 0.6.23-11.19.22
  • libavahi-common3 >= 0.6.23-11.19.22
  • libavahi-common3-32bit >= 0.6.23-11.19.22
  • libavahi-common3-x86 >= 0.6.23-11.19.22
  • libavahi-core5 >= 0.6.23-11.19.22
  • libdns_sd >= 0.6.23-11.19.22
  • libdns_sd-32bit >= 0.6.23-11.19.22
  • libdns_sd-x86 >= 0.6.23-11.19.22
Patchnames:
SUSE Linux Enterprise Server 11 SP1 GA avahi
SUSE Linux Enterprise Server 11 SP2
  • avahi >= 0.6.23-11.19.22
  • avahi-lang >= 0.6.23-11.19.22
  • avahi-utils >= 0.6.23-11.19.22
  • libavahi-client3 >= 0.6.23-11.19.22
  • libavahi-client3-32bit >= 0.6.23-11.19.22
  • libavahi-client3-x86 >= 0.6.23-11.19.22
  • libavahi-common3 >= 0.6.23-11.19.22
  • libavahi-common3-32bit >= 0.6.23-11.19.22
  • libavahi-common3-x86 >= 0.6.23-11.19.22
  • libavahi-core5 >= 0.6.23-11.19.22
  • libdns_sd >= 0.6.23-11.19.22
  • libdns_sd-32bit >= 0.6.23-11.19.22
  • libdns_sd-x86 >= 0.6.23-11.19.22
Patchnames:
SUSE Linux Enterprise Server 11 SP2 GA avahi
SUSE Linux Enterprise Server 11 SP3
  • avahi >= 0.6.23-11.30.4
  • avahi-lang >= 0.6.23-11.30.4
  • avahi-utils >= 0.6.23-11.30.4
  • libavahi-client3 >= 0.6.23-11.30.4
  • libavahi-client3-32bit >= 0.6.23-11.30.4
  • libavahi-client3-x86 >= 0.6.23-11.30.4
  • libavahi-common3 >= 0.6.23-11.30.4
  • libavahi-common3-32bit >= 0.6.23-11.30.4
  • libavahi-common3-x86 >= 0.6.23-11.30.4
  • libavahi-core5 >= 0.6.23-11.30.4
  • libdns_sd >= 0.6.23-11.30.4
  • libdns_sd-32bit >= 0.6.23-11.30.4
  • libdns_sd-x86 >= 0.6.23-11.30.4
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA avahi
SUSE Linux Enterprise Server 11 SP4
  • avahi >= 0.6.23-11.32.1
  • avahi-lang >= 0.6.23-11.32.1
  • avahi-utils >= 0.6.23-11.32.1
  • libavahi-client3 >= 0.6.23-11.32.1
  • libavahi-client3-32bit >= 0.6.23-11.32.1
  • libavahi-client3-x86 >= 0.6.23-11.32.1
  • libavahi-common3 >= 0.6.23-11.32.1
  • libavahi-common3-32bit >= 0.6.23-11.32.1
  • libavahi-common3-x86 >= 0.6.23-11.32.1
  • libavahi-core5 >= 0.6.23-11.32.1
  • libdns_sd >= 0.6.23-11.32.1
  • libdns_sd-32bit >= 0.6.23-11.32.1
  • libdns_sd-x86 >= 0.6.23-11.32.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA avahi
SUSE Linux Enterprise Software Development Kit 11 SP4
  • avahi-compat-howl-devel >= 0.6.23-11.32.1
  • avahi-compat-mDNSResponder-devel >= 0.6.23-11.32.1
  • libavahi-devel >= 0.6.23-11.32.1
  • libhowl0 >= 0.6.23-11.32.1
  • python-avahi >= 0.6.23-11.32.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA avahi-compat-howl-devel
openSUSE 11.0
  • avahi-debuginfo >= 0.6.22-68.2
  • avahi-debugsource >= 0.6.22-68.2
  • avahi-qt4-debuginfo >= 0.6.22-8.2
  • avahi-qt4-debugsource >= 0.6.22-8.2
openSUSE 11.0
  • avahi >= 0.6.22-68.2
  • avahi-compat-howl-devel >= 0.6.22-68.2
  • avahi-compat-mDNSResponder-devel >= 0.6.22-68.2
  • avahi-utils >= 0.6.22-68.2
  • avahi-utils-gtk >= 0.6.22-68.2
  • libavahi-client3 >= 0.6.22-68.2
  • libavahi-client3-32bit >= 0.6.22-68.2
  • libavahi-client3-64bit >= 0.6.22-68.2
  • libavahi-common3 >= 0.6.22-68.2
  • libavahi-common3-32bit >= 0.6.22-68.2
  • libavahi-common3-64bit >= 0.6.22-68.2
  • libavahi-core5 >= 0.6.22-68.2
  • libavahi-devel >= 0.6.22-68.2
  • libavahi-glib-devel >= 0.6.22-68.2
  • libavahi-glib1 >= 0.6.22-68.2
  • libavahi-glib1-32bit >= 0.6.22-68.2
  • libavahi-glib1-64bit >= 0.6.22-68.2
  • libavahi-gobject-devel >= 0.6.22-68.2
  • libavahi-gobject0 >= 0.6.22-68.2
  • libavahi-ui0 >= 0.6.22-68.2
  • libdns_sd >= 0.6.22-68.2
  • libdns_sd-32bit >= 0.6.22-68.2
  • libdns_sd-64bit >= 0.6.22-68.2
  • libhowl0 >= 0.6.22-68.2
  • python-avahi >= 0.6.22-68.2
openSUSE 11.1
  • avahi >= 0.6.23-9.1
  • avahi-compat-howl-devel >= 0.6.23-9.1
  • avahi-compat-mDNSResponder-devel >= 0.6.23-9.1
  • avahi-debuginfo >= 0.6.23-9.1
  • avahi-debugsource >= 0.6.23-9.1
  • avahi-qt4-debuginfo >= 0.6.23-9.1
  • avahi-qt4-debugsource >= 0.6.23-9.1
  • avahi-utils >= 0.6.23-9.1
  • libavahi-client3 >= 0.6.23-9.1
  • libavahi-client3-32bit >= 0.6.23-9.1
  • libavahi-common3 >= 0.6.23-9.1
  • libavahi-common3-32bit >= 0.6.23-9.1
  • libavahi-core5 >= 0.6.23-9.1
  • libavahi-devel >= 0.6.23-9.1
  • libavahi-glib-devel >= 0.6.23-9.1
  • libavahi-glib1 >= 0.6.23-9.1
  • libavahi-glib1-32bit >= 0.6.23-9.1
  • libavahi-gobject-devel >= 0.6.23-9.1
  • libavahi-gobject0 >= 0.6.23-9.1
  • libavahi-ui0 >= 0.6.23-9.1
  • libdns_sd >= 0.6.23-9.1
  • libdns_sd-32bit >= 0.6.23-9.1
  • libhowl0 >= 0.6.23-9.1
  • python-avahi >= 0.6.23-9.1
openSUSE 11.1
  • avahi >= 0.6.23-9.1
  • avahi-compat-howl-devel >= 0.6.23-9.1
  • avahi-compat-mDNSResponder-devel >= 0.6.23-9.1
  • avahi-utils >= 0.6.23-9.1
  • libavahi-client3 >= 0.6.23-9.1
  • libavahi-client3-32bit >= 0.6.23-9.1
  • libavahi-client3-64bit >= 0.6.23-9.2
  • libavahi-common3 >= 0.6.23-9.1
  • libavahi-common3-32bit >= 0.6.23-9.1
  • libavahi-common3-64bit >= 0.6.23-9.2
  • libavahi-core5 >= 0.6.23-9.1
  • libavahi-devel >= 0.6.23-9.1
  • libavahi-glib-devel >= 0.6.23-9.1
  • libavahi-glib1 >= 0.6.23-9.1
  • libavahi-glib1-32bit >= 0.6.23-9.1
  • libavahi-glib1-64bit >= 0.6.23-9.1
  • libavahi-gobject-devel >= 0.6.23-9.1
  • libavahi-gobject0 >= 0.6.23-9.1
  • libavahi-ui0 >= 0.6.23-9.1
  • libdns_sd >= 0.6.23-9.1
  • libdns_sd-32bit >= 0.6.23-9.1
  • libdns_sd-64bit >= 0.6.23-9.2
  • libhowl0 >= 0.6.23-9.1
  • python-avahi >= 0.6.23-9.1
SUSE Linux Enterprise SDK 10 SP2
  • avahi >= 0.6.5-29.19
  • avahi-devel >= 0.6.5-29.19
  • avahi-glib >= 0.6.5-29.19
sle10-sp2-sdk.x86-64
sle10-sp2-sdk.x86
sle10-sp2-sdk.ppc
sled10-sp2.x86-64
sle10-sp2-sdk.ia64
sle10-sp2-sdk.s390x
sled10-sp2.x86
ZYPP Patch Nr: 5870