漏洞信息详情
Avahi Compressed 'avahi-core/dns.c'DNS拒绝服务漏洞
漏洞简介
Avahi0.6.16之前版本中的avahi-core/dns.c中的consume_labels函数可通过带有指向自己的标签的特制压缩DNS响应来发起拒绝服务攻击(无限循环)。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Avahi Avahi 0.6.10
Avahi avahi-0.6.16.tar.gz
http://avahi.org/download/avahi-0.6.16.tar.gz
Avahi Avahi 0.6.11
RedHat avahi-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-0.6.16-1.fc6.src.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-howl-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-howl-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-howl-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-howl-devel-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-howl-devel-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-howl-devel-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-libdns_sd-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-libdns_sd-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-libdns_sd-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-libdns_sd-devel-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-libdns_sd-devel-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-compat-libdns_sd-devel-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-debuginfo-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-debuginfo-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-debuginfo-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-devel-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-devel-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-devel-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-glib-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-glib-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-glib-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-glib-devel-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-glib-devel-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-glib-devel-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-qt3-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-qt3-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-qt3-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-qt3-devel-0.6.16-1.fc6.i386.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-qt3-devel-0.6.16-1.fc6.ppc.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-qt3-devel-0.6.16-1.fc6.x86_64.rpm
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/6/
RedHat avahi-sharp-0.6.16-1.fc6.i386.rpm
http://downloa
参考网址
来源: www.avahi.org
链接:http://www.avahi.org/ticket/84
来源: www.avahi.org
链接:http://www.avahi.org/#December2006
来源: www.avahi.org
链接:http://www.avahi.org/changeset/1340
来源: UBUNTU
名称: USN-402-1
链接:http://www.ubuntu.com/usn/usn-402-1
来源: BID
名称: 21881
链接:http://www.securityfocus.com/bid/21881
来源: SUSE
名称: SUSE-SR:2007:007
链接:http://www.novell.com/linux/security/advisories/2007_007_suse.html
来源: MANDRIVA
名称: MDKSA-2007:003
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2007:003
来源: VUPEN
名称: ADV-2007-0071
链接:http://www.frsirt.com/english/advisories/2007/0071
来源: SECUNIA
名称: 24995
链接:http://secunia.com/advisories/24995
来源: SECUNIA
名称: 23782
链接:http://secunia.com/advisories/23782
来源: SECUNIA
名称: 23673
链接:http://secunia.com/advisories/23673
来源: SECUNIA
名称: 23660
链接:http://secunia.com/advisories/23660
来源: SECUNIA
名称: 23644
链接:http://secunia.com/advisories/23644
来源: SECUNIA
名称: 23628
链接:http://secunia.com/advisories/23628
来源: MANDRIVA
名称: MDKSA-2007:003
链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2007:003
来源: FEDORA
名称: FEDORA-2007-019
链接:http://fedoranews.org/cms/node/2408
来源: FEDORA
名称: FEDORA-2007-018
链接:http://fedoranews.org/cms/node/2362
受影响实体
- Avahi Avahi:0.6.9<!--2000-1-1-->
- Avahi Avahi:0.6.7<!--2000-1-1-->
- Avahi Avahi:0.6.8<!--2000-1-1-->
- Avahi Avahi:0.6.15<!--2000-1-1-->
- Avahi Avahi:0.6.14<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...