Opened 6 months ago

Closed 6 weeks ago

#23150 closed enhancement (fixed)

Fix numerous CVEs in Avahi

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

While reviewing my email this morning, I noticed that I got another email from oss-security regarding a security vulnerability in Avahi.

At that point I decided to take a look at ​https://github.com/avahi/avahi/security and see what we are missing. Currently we only have a fix for CVE-2021-3468. There is one vulnerability there on the second page which is unpatched and has no CVE but it's impact is extremely minor so I don't think it's worth waiting on at the moment.

These vulnerabilities have been fixed in a release candidate version of Avahi, but it's probably best to stay with the released version from 2020 for now. There is an additional CVE which still has a PR going through review that could allow for all system file descriptors to be drained via an extremely easy local DoS, but it is having both CI problems and issues with breaking Avahi on other platforms. For anyone interested, that is ​https://github.com/avahi/avahi/security/advisories/GHSA-73wf-3xmj-x82q

We will need to fix the following vulnerabilities:

Note that the above issue was discovered and resolved by the head of the Vulnerability Operations Center for a cybersecurity company in France.

As usual with Avahi, things are quite a mess upstream. They have been trying to get a new release out (0.9) and it is now well over a year overdue. ​https://github.com/avahi/avahi/issues/503

If you check the issue linked above, please ignore CVE-2021-26720. It is specific to how Debian is packaging it.

We should resolve these however so we're on the same page as other distributions and because this package has been unmaintained for so long. The denial of service issues above can be exploited pretty easily by users for the most part, and there are also DNS spoofing issues for some configurations.

Change History (6)

comment:1 by Bruce Dubbs, 5 months ago

We could do like arch and use v0.9-rc4 (April 1st)

​https://github.com/avahi/avahi/tags

comment:2 by Bruce Dubbs, 5 months ago

Owner: changed from blfs-book to Douglas R. Reno

comment:3 by Douglas R. Reno, 5 months ago

Status: new → assigned

comment:4 by Douglas R. Reno, 4 months ago

Owner: changed from Douglas R. Reno to blfs-book
Status: assigned → new

I'm going to reassign these to the book for now so whoever wants to do them can do them.

In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.

comment:5 by Douglas R. Reno, 4 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:6 by Bruce Dubbs, 6 weeks ago

Resolution: → fixed
Status: assigned → closed

I've installed the -rc5 version of this package and will mark this fixed. If there are any new security issues that need to be patched, then a new ticket should be created.

Fixed at commit df8a82caf0.

Note: See TracTickets for help on using tickets.