[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1016837: bullseye-pu: package avahi/0.8-5+deb11u1



Control: tags -1 + confirmed

On Mon, 2022-08-08 at 11:35 +0200, Michael Biebl wrote:
> avahi (0.8-5+deb11u1) bullseye; urgency=medium
> 
>   [ Simon McVittie ]
>   * Add patch to fix display of URLs containing '&' in avahi-
> discover.
>     Otherwise, a TXT entry containing a URL with '&' will cause an
> error.
> 
>   [ Michael Biebl ]
>   * Do not disable timeout cleanup on watch cleanup.
>     This was causing timeouts to never be removed from the linked
> list that
>     tracks them, resulting in both memory and CPU usage to grow
> larger over
>     time. Thanks to Gustavo Noronha Silva. (Closes: #993051)
>   * Fix NULL pointer crashes when trying to resolve badly-formatted
> hostnames.
>     Fixes a local DoS in avahi-daemon that can be triggered by trying
> to
>     resolve badly-formatted hostnames on the /run/avahi-daemon/socket
>     interface. (CVE-2021-3502, Closes: #986018)
> 

Please go ahead.

Regards,

Adam


Reply to: