[Pkg-utopia-maintainers] Bug#917047: avahi: CVE-2018-1000845: DNS amplification and reflection to spoofed addresses

Salvatore Bonaccorso carnil at debian.org
Fri Dec 21 23:06:45 GMT 2018


Source: avahi
Version: 0.6.32-2
Severity: important
Tags: security upstream
Forwarded: https://github.com/lathiat/avahi/issues/203
Control: found -1 0.7-4

Hi,

The following vulnerability was published for avahi, filling to start
tracking the issue.

CVE-2018-1000845[0]:
| Avahi version 0.7 contains a Incorrect Access Control vulnerability in
| avahi-daemon that can result in Traffic reflection and amplification
| for DDoS attacks.. This attack appear to be exploitable via unicast IP
| network packet with spoofed source address.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-1000845
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000845
[1] https://github.com/lathiat/avahi/issues/203
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1661252

Regards,
Salvatore



More information about the Pkg-utopia-maintainers mailing list