Bug 24308 - CVE-2010-2244: assertion failure after receiving a packet with corrupted checksum
Summary: CVE-2010-2244: assertion failure after receiving a packet with corrupted chec...
Status: CLOSED FIXED
Alias: None
Product: Sisyphus
Classification: Development
Component: avahi (show other bugs)
Version: unstable
Hardware: all Linux
: P3 blocker
Assignee: Sergey Bolshakov
QA Contact: qa-sisyphus
URL: http://cve.mitre.org/cgi-bin/cvename....
Keywords: security
Depends on: 24354
Blocks:
  Show dependency tree
 
Reported: 2010-10-15 09:22 MSD by Vladimir Lettiev
Modified: 2010-10-21 08:52 MSD (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Vladimir Lettiev 2010-10-15 09:22:26 MSD
The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum

Fixed in Avahi >= 0.6.26
Comment 1 Vladimir Lettiev 2010-10-20 09:41:43 MSD
0.6.28-alt2 в Sisyphus. Как я понимаю можно закрывать баг?
Comment 2 Sergey Bolshakov 2010-10-20 14:11:19 MSD
да