Lucene search

K
ubuntuUbuntuUSN-380-1
HistoryNov 11, 2006 - 12:00 a.m.

Avahi vulnerability

2006-11-1100:00:00
ubuntu.com
35

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

10.1%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06
  • Ubuntu 5.10

Details

Steve Grubb discovered that netlink messages were not being checked for
their sender identity. This could lead to local users manipulating the
Avahi service.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchavahi-daemon< 0.6.13-2ubuntu2.2UNKNOWN
Ubuntu6.10noarchlibavahi-core4< 0.6.13-2ubuntu2.2UNKNOWN
Ubuntu6.06noarchavahi-daemon< 0.6.10-0ubuntu3.2UNKNOWN
Ubuntu6.06noarchlibavahi-core4< 0.6.10-0ubuntu3.2UNKNOWN
Ubuntu5.10noarchavahi-daemon< 0.5.2-1ubuntu1.2UNKNOWN
Ubuntu5.10noarchlibavahi-core1< 0.5.2-1ubuntu1.2UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

10.1%