CVE Vulnerabilities

CVE-2006-6870

Published: Dec 31, 2006 | Modified: Mar 08, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.

Affected Software

Name Vendor Start Version End Version
Avahi Avahi 0.6.7 (including) 0.6.7 (including)
Avahi Avahi 0.6.8 (including) 0.6.8 (including)
Avahi Avahi 0.6.9 (including) 0.6.9 (including)
Avahi Avahi 0.6.10 (including) 0.6.10 (including)
Avahi Avahi 0.6.11 (including) 0.6.11 (including)
Avahi Avahi 0.6.12 (including) 0.6.12 (including)
Avahi Avahi 0.6.13 (including) 0.6.13 (including)
Avahi Avahi 0.6.14 (including) 0.6.14 (including)
Avahi Avahi 0.6.15 (including) 0.6.15 (including)
Avahi Ubuntu dapper *
Avahi Ubuntu edgy *
Avahi Ubuntu upstream *

References