This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.
Details follow:
Emanuele Aina discovered that Avahi did not properly validate it's input when processing data over D-Bus. A local attacker could send an empty TXT message via D-Bus and cause a denial of service (failed assertion). This issue only affected Ubuntu 6.06 LTS. (CVE-2007-3372)
Hugo Dias discovered that Avahi did not properly verify it's input when processing mDNS packets. A remote attacker could send a crafted mDNS packet and cause a denial of service (assertion failure). (CVE-2008-5081)
Solution: The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS: avahi-daemon 0.6.10-0ubuntu3.5
Ubuntu 7.10: avahi-daemon 0.6.20-2ubuntu3.4
Ubuntu 8.04 LTS: avahi-daemon 0.6.22-2ubuntu4.1
Ubuntu 8.10: avahi-daemon 0.6.23-2ubuntu2.1
In general, a standard system upgrade is sufficient to effect the necessary changes.