CVE Vulnerabilities

CVE-2006-6870

Published: Dec 31, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.

Affected Software

NameVendorStart VersionEnd Version
AvahiAvahi0.6.7 (including)0.6.7 (including)
AvahiAvahi0.6.8 (including)0.6.8 (including)
AvahiAvahi0.6.9 (including)0.6.9 (including)
AvahiAvahi0.6.10 (including)0.6.10 (including)
AvahiAvahi0.6.11 (including)0.6.11 (including)
AvahiAvahi0.6.12 (including)0.6.12 (including)
AvahiAvahi0.6.13 (including)0.6.13 (including)
AvahiAvahi0.6.14 (including)0.6.14 (including)
AvahiAvahi0.6.15 (including)0.6.15 (including)
AvahiUbuntudapper*
AvahiUbuntuedgy*
AvahiUbuntuupstream*

References