CVE-2006-5461
https://notcve.org/view.php?id=CVE-2006-5461
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi. Avahi anterior a 0.6.15 no verifica la identidad del remitente de mensajes netlink para asegurar que provienen del núcleo en lugar que de otro proceso, lo cual permite a usuarios locales suplantar cambios de red en Avahi. • http://avahi.org/milestone/Avahi%200.6.15 http://secunia.com/advisories/22807 http://secunia.com/advisories/22852 http://secunia.com/advisories/22932 http://secunia.com/advisories/23020 http://secunia.com/advisories/23042 http://securitytracker.com/id?1017257 http://www.gentoo.org/security/en/glsa/glsa-200611-13.xml http://www.mandriva.com/security/advisories?name=MDKSA-2006:215 http://www.novell.com/linux/security/advisories/2006_26_sr.html http://www.securityfocus.com& •
CVE-2006-2288
https://notcve.org/view.php?id=CVE-2006-2288
Avahi before 0.6.10 allows local users to cause a denial of service (mDNS/DNS-SD service disconnect) via unspecified mDNS name conflicts. • http://0pointer.de/cgi-bin/viewcvs.cgi/%2Acheckout%2A/trunk/docs/NEWS?root=avahi http://secunia.com/advisories/20022 http://secunia.com/advisories/20215 http://www.novell.com/linux/security/advisories/2006_05_19.html http://www.securityfocus.com/bid/17884 https://exchange.xforce.ibmcloud.com/vulnerabilities/26330 •
CVE-2006-2289
https://notcve.org/view.php?id=CVE-2006-2289
Buffer overflow in avahi-core in Avahi before 0.6.10 allows local users to execute arbitrary code via unknown vectors. • http://0pointer.de/cgi-bin/viewcvs.cgi/%2Acheckout%2A/trunk/docs/NEWS?root=avahi http://secunia.com/advisories/20022 http://secunia.com/advisories/20215 http://www.novell.com/linux/security/advisories/2006_05_19.html http://www.securityfocus.com/bid/17884 https://exchange.xforce.ibmcloud.com/vulnerabilities/26331 •