LWN.net Logo

avahi: denial of service

Package(s):avahi CVE #(s):CVE-2011-1002
Created:February 24, 2011 Updated:September 12, 2011
Description:

From the Mandriva advisory:

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244 (CVE-2011-1002).

Alerts:
Gentoo 201110-17 2011-10-22
Fedora FEDORA-2011-11588 2011-08-26
CentOS CESA-2011:0436 2011-04-14
Red Hat RHSA-2011:0436-01 2011-04-12
Pardus 2011-64 2011-04-07
SUSE SUSE-SR:2011:005 2011-04-01
Red Hat RHSA-2011:0779-01 2011-05-19
Ubuntu USN-1084-1 2011-03-07
openSUSE openSUSE-SU-2011:0149-1 2011-03-02
Debian DSA-2174-1 2011-02-26
Mandriva MDVSA-2011:037 2011-02-24
Pardus 2011-67 2011-04-07

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds