853cff9679
Fixes CVE-2017-6519: avahi-daemon in Avahi through 0.6.32 and 0.7
inadvertently responds to IPv6 unicast queries with source addresses
that are not on-link, which allows remote attackers to cause a denial
of service (traffic amplification) and may cause information leakage
by obtaining potentially sensitive information from the responding
device via port-5353 UDP packets.
Signed-off-by: Artem Panfilov <panfilov.artyom@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
(cherry picked from commit
|
||
---|---|---|
.. | ||
0001-Drop-legacy-unicast-queries-from-address-not-on-loca.patch | ||
avahi_sysusers.conf | ||
avahi_tmpfiles.conf | ||
avahi.hash | ||
avahi.mk | ||
Config.in | ||
S05avahi-setup.sh | ||
S50avahi-daemon |