dwww Home | Show directory contents | Find package

avahi (0.8-5ubuntu5.2) jammy-security; urgency=medium

  * SECURITY UPDATE: Reachable assertions exist in server functions of
    avahi-core
    - debian/patches/CVE-2023-38469-1.patch: reject overly long TXT 
      resource records
    - debian/patches/CVE-2023-38469-2.patch: tests: pass overly long TXT
      resource records
    - CVE-2023-38469

  * SECURITY UPDATE: Reachable assertions exist in domain functions in 
    avahi-common
    - debian/patches/CVE-2023-38470-1.patch: Ensure each label is at least
      one byte long
    - debian/patches/CVE-2023-38470-2.patch: bail out when escaped labels 
      can't fit into ret
    - CVE-2023-38470

  * SECURITY UPDATE: Reachable assertions exist in server functions in 
    avahi-core
    - debian/patches/CVE-2023-38471-1.patch: core: extract host name using
      avahi_unescape_label()
    - debian/patches/CVE-2023-38471-2.patch: core: return errors from 
      avahi_server_set_host_name properly
    - CVE-2023-38471

  * SECURITY UPDATE: Reachable assertions exist in dbus functions in 
    avahi-daemon
    - debian/patches/CVE-2023-38472.patch: core: make sure there is rdata 
      to process before parsing it
    - CVE-2023-38472

  * SECURITY UPDATE: Reachable assertions exist in alternative functions 
    in avahi-common
    - debian/patches/CVE-2023-38473.patch: common: derive alternative host
      name from its unescaped version
    - CVE-2023-38473

 -- Nick Galanis <nick.galanis@canonical.com>  Thu, 16 Nov 2023 16:37:03 +0000

avahi (0.8-5ubuntu5.1) jammy-security; urgency=medium

  * SECURITY UPDATE: avahi-daemon can be crashed via DBus
    - debian/patches/CVE-2023-1981.patch: emit error if requested service
      is not found in avahi-daemon/dbus-protocol.c.
    - CVE-2023-1981

 -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Wed, 31 May 2023 09:57:11 -0400

avahi (0.8-5ubuntu5) jammy; urgency=medium

  * No-change rebuild for ppc64el baseline bump.

 -- Ɓukasz 'sil2100' Zemczak <lukasz.zemczak@ubuntu.com>  Wed, 23 Mar 2022 10:42:05 +0100

avahi (0.8-5ubuntu4) impish; urgency=medium

  * SECURITY UPDATE: DoS in avahi_s_host_name_resolver_start
    - debian/patches/CVE-2021-3502.patch: fix multiple null pointer crashes
      in avahi-core/browse-dns-server.c, avahi-core/browse-domain.c,
      avahi-core/browse-service-type.c, avahi-core/browse-service.c,
      avahi-core/browse.c, avahi-core/resolve-address.c,
      avahi-core/resolve-host-name.c, avahi-core/resolve-service.c.
    - CVE-2021-3502

 -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Tue, 06 Jul 2021 10:13:47 -0400

avahi (0.8-5ubuntu3) hirsute; urgency=medium

  * avahi-daemon-chroot-fix-bogus-assignments-in-assertions.patch,
    avahi-client-fix-resource-leak.patch: Issues discovered by static analysis
    (Upstream pull request #202).
  * avoid-infinite-loop-in-avahi-daemon-by-handling-hup-event-in-client-work.patch:
    Avoid infinite-loop in avahi-daemon by handling HUP event in client_work()
    (Upstream pull request #330).

 -- Till Kamppeter <till.kamppeter@gmail.com>  Thu,  8 Apr 2021 15:24:07 +0200

avahi (0.8-5ubuntu2) hirsute; urgency=medium

  * Disable lto. See https://bugzilla.redhat.com/show_bug.cgi?id=1907727.

 -- Matthias Klose <doko@ubuntu.com>  Mon, 22 Mar 2021 20:47:51 +0100

avahi (0.8-5ubuntu1) hirsute; urgency=low

  * Merge from Debian unstable. Remaining changes:
    - debian/avahi-daemon.postinst: remove the deprecated conffiles
      if-up/down entries on upgrade, use a simple logic and no
      dpkg-maintscript-helper since there is no configuration worth saving

 -- Till Kamppeter <till.kamppeter@gmail.com>  Wed, 24 Feb 2021 23:53:07 +0100

avahi (0.8-5) unstable; urgency=medium

  * d/avahi-daemon.maintscript: Drop removal of symlink, they're not normal
    config files.
  * d/avahi-daemon.postinst: Clean up left-over dpkg-backup symlink from 0.8.3
    to 0.8.4 symlink (Closes: #982016)

 -- Sjoerd Simons <sjoerd@debian.org>  Sat, 06 Feb 2021 16:05:37 +0100

avahi (0.8-4) unstable; urgency=medium

  [ Sjoerd Simons ]
  * Team upload

  [ Simon McVittie ]
  * Remove avahi-daemon-check-dns mechanism, no longer needed.
    Thanks to Trent Lloyd, Sebastien Bacher (LP: #1870824)
    (Closes: #433945, #559927, #629509, #747895, #878586, #898038, #929010)

 -- Sjoerd Simons <sjoerd@debian.org>  Fri, 05 Feb 2021 09:21:16 +0100

avahi (0.8-3ubuntu2) hirsute; urgency=medium

  * debian/avahi-daemon.links:
    - remove buggy symlink, the target doesn't exist anymore (lp: #1901090)
  * debian/avahi-daemon.postinst:
    - remove the deprecated conffiles if-up/down entries on upgrade,
      use a simple logic and no dpkg-maintscript-helper since there is no
      configuration worth saving

 -- Sebastien Bacher <seb128@ubuntu.com>  Tue, 10 Nov 2020 15:03:56 +0100

# For older changelog entries, run 'apt-get changelog libavahi-common-data'

Generated by dwww version 1.14 on Sun Feb 2 14:10:20 CET 2025.