Executive Summary
Informations | |||
---|---|---|---|
Name | MDVSA-2010:204 | First vendor Publication | 2010-10-14 |
Vendor | Mandriva | Last vendor Modification | 2010-10-14 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:P) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A vulnerability was discovered and corrected in avahi: The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081 (CVE-2010-2244). Packages for 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more: http://store.mandriva.com/product_info.php?cPath=149&products_id=490 The updated packages have been patched to correct this issue. |
Original Source
Url : http://www.mandriva.com/security/advisories?name=MDVSA-2010:204 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-399 | Resource Management Errors |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:17706 | |||
Oval ID: | oval:org.mitre.oval:def:17706 | ||
Title: | USN-696-1 -- avahi vulnerabilities | ||
Description: | Emanuele Aina discovered that Avahi did not properly validate it's input when processing data over D-Bus. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-696-1 CVE-2007-3372 CVE-2008-5081 | Version: | 7 |
Platform(s): | Ubuntu 6.06 Ubuntu 7.10 Ubuntu 8.04 Ubuntu 8.10 | Product(s): | avahi |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:18697 | |||
Oval ID: | oval:org.mitre.oval:def:18697 | ||
Title: | DSA-1690-1 avahi - denial of service | ||
Description: | Two denial of service conditions were discovered in avahi, a Multicast DNS implementation. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1690-1 CVE-2007-3372 CVE-2008-5081 | Version: | 7 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | avahi |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:22345 | |||
Oval ID: | oval:org.mitre.oval:def:22345 | ||
Title: | RHSA-2010:0528: avahi security update (Moderate) | ||
Description: | The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2010:0528-01 CESA-2010:0528 CVE-2009-0758 CVE-2010-2244 | Version: | 29 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | avahi |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:29261 | |||
Oval ID: | oval:org.mitre.oval:def:29261 | ||
Title: | RHSA-2009:0013 -- avahi security update (Moderate) | ||
Description: | Updated avahi packages that fix a security issue are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. Avahi is an implementation of the DNS Service Discovery and Multicast DNS specifications for Zeroconf Networking. It facilitates service discovery on a local network. Avahi and Avahi-aware applications allow you to plug your computer into a network and, with no configuration, view other people to chat with, see printers to print to, and find shared files on other computers. Hugo Dias discovered a denial of service flaw in avahi-daemon. A remote attacker on the same local area network (LAN) could send a specially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemon to exit unexpectedly due to a failed assertion check. (CVE-2008-5081) All users are advised to upgrade to these updated packages, which contain a backported patch which resolves this issue. After installing the update, avahi-daemon will be restarted automatically. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2009:0013 CESA-2009:0013-CentOS 5 CVE-2008-5081 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | avahi |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:9987 | |||
Oval ID: | oval:org.mitre.oval:def:9987 | ||
Title: | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure. | ||
Description: | The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2008-5081 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2008-12-19 | Avahi < 0.6.24 (mDNS Daemon) Remote Denial of Service Exploit |
OpenVAS Exploits
Date | Description |
---|---|
2012-07-30 | Name : CentOS Update for avahi CESA-2011:0436 centos5 x86_64 File : nvt/gb_CESA-2011_0436_avahi_centos5_x86_64.nasl |
2012-06-06 | Name : RedHat Update for avahi RHSA-2011:0779-01 File : nvt/gb_RHSA-2011_0779-01_avahi.nasl |
2012-02-12 | Name : Gentoo Security Advisory GLSA 201110-17 (avahi) File : nvt/glsa_201110_17.nasl |
2011-09-12 | Name : Fedora Update for avahi FEDORA-2011-11588 File : nvt/gb_fedora_2011_11588_avahi_fc14.nasl |
2011-08-09 | Name : CentOS Update for avahi CESA-2009:0013 centos5 i386 File : nvt/gb_CESA-2009_0013_avahi_centos5_i386.nasl |
2011-08-09 | Name : CentOS Update for avahi CESA-2010:0528 centos5 i386 File : nvt/gb_CESA-2010_0528_avahi_centos5_i386.nasl |
2011-08-09 | Name : CentOS Update for avahi CESA-2011:0436 centos5 i386 File : nvt/gb_CESA-2011_0436_avahi_centos5_i386.nasl |
2011-05-12 | Name : avahi -- denial of service File : nvt/freebsd_avahi.nasl |
2011-04-19 | Name : RedHat Update for avahi RHSA-2011:0436-01 File : nvt/gb_RHSA-2011_0436-01_avahi.nasl |
2011-02-28 | Name : Mandriva Update for avahi MDVSA-2011:037 (avahi) File : nvt/gb_mandriva_MDVSA_2011_037.nasl |
2010-10-19 | Name : Mandriva Update for avahi MDVSA-2010:204 (avahi) File : nvt/gb_mandriva_MDVSA_2010_204.nasl |
2010-10-01 | Name : Ubuntu Update for avahi vulnerabilities USN-992-1 File : nvt/gb_ubuntu_USN_992_1.nasl |
2010-08-21 | Name : Debian Security Advisory DSA 2086-1 (avahi) File : nvt/deb_2086_1.nasl |
2010-07-16 | Name : RedHat Update for avahi RHSA-2010:0528-01 File : nvt/gb_RHSA-2010_0528-01_avahi.nasl |
2010-07-12 | Name : Fedora Update for avahi FEDORA-2010-10581 File : nvt/gb_fedora_2010_10581_avahi_fc13.nasl |
2010-07-12 | Name : Fedora Update for avahi FEDORA-2010-10584 File : nvt/gb_fedora_2010_10584_avahi_fc12.nasl |
2009-06-05 | Name : Ubuntu USN-698-1 (nagios) File : nvt/ubuntu_698_1.nasl |
2009-03-23 | Name : Ubuntu Update for avahi vulnerabilities USN-696-1 File : nvt/gb_ubuntu_USN_696_1.nasl |
2009-02-02 | Name : Mandrake Security Advisory MDVSA-2009:031 (avahi) File : nvt/mdksa_2009_031.nasl |
2009-02-02 | Name : SuSE Security Summary SUSE-SR:2009:003 File : nvt/suse_sr_2009_003.nasl |
2009-01-20 | Name : Gentoo Security Advisory GLSA 200901-11 (avahi) File : nvt/glsa_200901_11.nasl |
2009-01-20 | Name : CentOS Security Advisory CESA-2009:0013 (avahi) File : nvt/ovcesa2009_0013.nasl |
2009-01-13 | Name : RedHat Security Advisory RHSA-2009:0013 File : nvt/RHSA_2009_0013.nasl |
2009-01-07 | Name : Fedora Core 10 FEDORA-2008-11351 (avahi) File : nvt/fcore_2008_11351.nasl |
2008-12-31 | Name : Avahi Denial of Service Vulnerability File : nvt/secpod_avahi_dos_vuln.nasl |
2008-12-29 | Name : Ubuntu USN-698-2 (nagios3) File : nvt/ubuntu_698_2.nasl |
2008-12-29 | Name : Ubuntu USN-699-1 (blender) File : nvt/ubuntu_699_1.nasl |
2008-12-29 | Name : Ubuntu USN-697-1 (imlib2) File : nvt/ubuntu_697_1.nasl |
2008-12-29 | Name : Debian Security Advisory DSA 1690-1 (avahi) File : nvt/deb_1690_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
66038 | Avahi avahi-core/socket.c Multiple Function DNS Packet Remote DoS |
50929 | Avahi avahi-daemon avahi-core/server.c Crafted mDNS Packet Handling Remote DoS Avahi contains a flaw that may allow a remote denial of service. The issue can be triggered by a specially crafted mDNS packet with a source port of 0, and will result in loss of availability for the service. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-11-17 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0622.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2010-0528.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2009-0013.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20100713_avahi_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20090112_avahi_on_SL5_x.nasl - Type : ACT_GATHER_INFO |
2011-10-24 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201110-17.nasl - Type : ACT_GATHER_INFO |
2011-09-12 | Name : The remote Fedora host is missing a security update. File : fedora_2011-11588.nasl - Type : ACT_GATHER_INFO |
2011-03-15 | Name : The remote Fedora host is missing a security update. File : fedora_2011-3033.nasl - Type : ACT_GATHER_INFO |
2011-03-15 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_8b986a054dbe11e08b9a02e0184b8d35.nasl - Type : ACT_GATHER_INFO |
2011-02-25 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2011-037.nasl - Type : ACT_GATHER_INFO |
2011-01-27 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_avahi-5870.nasl - Type : ACT_GATHER_INFO |
2010-10-15 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2010-204.nasl - Type : ACT_GATHER_INFO |
2010-10-06 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-992-1.nasl - Type : ACT_GATHER_INFO |
2010-08-05 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2086.nasl - Type : ACT_GATHER_INFO |
2010-07-28 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2010-0528.nasl - Type : ACT_GATHER_INFO |
2010-07-16 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2010-0528.nasl - Type : ACT_GATHER_INFO |
2010-07-07 | Name : The remote Fedora host is missing a security update. File : fedora_2010-10581.nasl - Type : ACT_GATHER_INFO |
2010-07-07 | Name : The remote Fedora host is missing a security update. File : fedora_2010-10584.nasl - Type : ACT_GATHER_INFO |
2010-01-06 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-0013.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_avahi-081218.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_avahi-081218.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Fedora host is missing a security update. File : fedora_2008-11351.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-031.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-696-1.nasl - Type : ACT_GATHER_INFO |
2009-02-01 | Name : The remote openSUSE host is missing a security update. File : suse_avahi-5882.nasl - Type : ACT_GATHER_INFO |
2009-01-15 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200901-11.nasl - Type : ACT_GATHER_INFO |
2009-01-13 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-0013.nasl - Type : ACT_GATHER_INFO |
2008-12-22 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1690.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:41:48 |
|
2013-05-11 00:48:20 |
|