[Pkg-utopia-maintainers] Bug#984938: avahi-daemon: local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket

Salvatore Bonaccorso carnil at debian.org
Sat Mar 27 19:29:36 GMT 2021


Control: forwarded -1 https://github.com/lathiat/avahi/pull/330
Control: retitle -1 avahi: CVE-2021-3468: local DoS by event-busy-loop from writing long lines to /run/avahi-daemon/socket

On Fri, Mar 26, 2021 at 12:22:29PM +0100, Riccardo Schirone wrote:
> I have requested a CVE through Red Hat.
> 
> I'm proposing a patch upstream[1].
> Additional details about the flaw at [2].
> 
> [1] https://github.com/lathiat/avahi/pull/330
> [2] https://bugzilla.redhat.com/show_bug.cgi?id=1939614#c3

This has been assigned CVE-2021-3468.

Regards,
Salvatore



More information about the Pkg-utopia-maintainers mailing list