The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avahi-daemon | Avahi | 0.6.23 (including) | 0.6.23 (including) |
Red Hat Enterprise Linux 5 | RedHat | avahi-0:0.6.16-9.el5_5 | * |
Avahi | Ubuntu | dapper | * |
Avahi | Ubuntu | gutsy | * |
Avahi | Ubuntu | hardy | * |
Avahi | Ubuntu | intrepid | * |
Avahi | Ubuntu | jaunty | * |
Avahi | Ubuntu | upstream | * |