Change logs for avahi source package in Kinetic

  • avahi (0.8-6ubuntu1.22.10.1) kinetic-security; urgency=medium
    
      * SECURITY UPDATE: avahi-daemon can be crashed via DBus
        - debian/patches/CVE-2023-1981.patch: emit error if requested service
          is not found in avahi-daemon/dbus-protocol.c.
        - CVE-2023-1981
    
     -- Marc Deslauriers <email address hidden>  Wed, 31 May 2023 09:53:35 -0400
  • avahi (0.8-6ubuntu1) kinetic; urgency=medium
    
      * Merge from Debian unstable, remaining changes:
        + debian/avahi-daemon.postinst: remove the deprecated conffiles
          if-up/down entries on upgrade, use a simple logic and no
          dpkg-maintscript-helper since there is no configuration worth saving
        + Disable lto, see https://bugzilla.redhat.com/show_bug.cgi?id=1907727
        + avahi-daemon-chroot-fix-bogus-assignments-in-assertions.patch,
          avahi-client-fix-resource-leak.patch: Issues discovered by static analysis
          (Upstream pull request #202)
        + avoid-infinite-loop-in-avahi-daemon-by-handling-hup-event-in-client-work.patch:
          Avoid infinite-loop in avahi-daemon by handling HUP event in client_work()
          (Upstream pull request #330)
      * Dropped changes, included in Debian:
        + SECURITY UPDATE: DoS in avahi_s_host_name_resolver_start
    
    avahi (0.8-6) unstable; urgency=medium
    
      [ Luca Boccassi ]
      * avahi-daemon: depend on default-dbus-system-bus | dbus-system-bus.
        This allows the reference implementation to be removed if using a
        different system bus implementation such as dbus-broker.
        [smcv: Adjust commit message]
    
      [ Simon McVittie ]
      * Add patch to fix display of URLs containing '&' in avahi-discover
      * Standards-Version: 4.6.0 (no changes required)
      * Use recommended debhelper compat level 13
    
      [ Michael Biebl ]
      * Do not disable timeout cleanup on watch cleanup.
        This was causing timeouts to never be removed from the linked list that
        tracks them, resulting in both memory and CPU usage to grow larger over
        time. Thanks to Gustavo Noronha Silva (Closes: #993051)
      * Drop obsolete lsb-base Depends
      * Fix NULL pointer crashes when trying to resolve badly-formatted hostnames.
        Fixes a local DoS in avahi-daemon that can be triggered by trying to
        resolve badly-formatted hostnames on the /run/avahi-daemon/socket
        interface. (CVE-2021-3502, Closes: #986018)
    
     -- Graham Inggs <email address hidden>  Mon, 22 Aug 2022 12:33:46 +0000
  • avahi (0.8-5ubuntu5) jammy; urgency=medium
    
      * No-change rebuild for ppc64el baseline bump.
    
     -- Ɓukasz 'sil2100' Zemczak <email address hidden>  Wed, 23 Mar 2022 10:42:05 +0100