CVE Vulnerabilities

CVE-2011-1002

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Feb 22, 2011 | Modified: Dec 22, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
3.3 MODERATE
AV:A/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Avahi Avahi * 0.6.28 (including)
Avahi Avahi 0.1 (including) 0.1 (including)
Avahi Avahi 0.2 (including) 0.2 (including)
Avahi Avahi 0.3 (including) 0.3 (including)
Avahi Avahi 0.4 (including) 0.4 (including)
Avahi Avahi 0.5 (including) 0.5 (including)
Avahi Avahi 0.5.1 (including) 0.5.1 (including)
Avahi Avahi 0.5.2 (including) 0.5.2 (including)
Avahi Avahi 0.6.1 (including) 0.6.1 (including)
Avahi Avahi 0.6.2 (including) 0.6.2 (including)
Avahi Avahi 0.6.3 (including) 0.6.3 (including)
Avahi Avahi 0.6.4 (including) 0.6.4 (including)
Avahi Avahi 0.6.5 (including) 0.6.5 (including)
Avahi Avahi 0.6.6 (including) 0.6.6 (including)
Avahi Avahi 0.6.7 (including) 0.6.7 (including)
Avahi Avahi 0.6.8 (including) 0.6.8 (including)
Avahi Avahi 0.6.9 (including) 0.6.9 (including)
Avahi Avahi 0.6.10 (including) 0.6.10 (including)
Avahi Avahi 0.6.11 (including) 0.6.11 (including)
Avahi Avahi 0.6.12 (including) 0.6.12 (including)
Avahi Avahi 0.6.13 (including) 0.6.13 (including)
Avahi Avahi 0.6.14 (including) 0.6.14 (including)
Avahi Avahi 0.6.15 (including) 0.6.15 (including)
Avahi Avahi 0.6.16 (including) 0.6.16 (including)
Avahi Avahi 0.6.17 (including) 0.6.17 (including)
Avahi Avahi 0.6.18 (including) 0.6.18 (including)
Avahi Avahi 0.6.19 (including) 0.6.19 (including)
Avahi Avahi 0.6.20 (including) 0.6.20 (including)
Avahi Avahi 0.6.21 (including) 0.6.21 (including)
Avahi Avahi 0.6.22 (including) 0.6.22 (including)
Avahi Avahi 0.6.23 (including) 0.6.23 (including)
Avahi Avahi 0.6.24 (including) 0.6.24 (including)
Avahi Avahi 0.6.25 (including) 0.6.25 (including)
Avahi Avahi 0.6.26 (including) 0.6.26 (including)
Avahi Avahi 0.6.27 (including) 0.6.27 (including)
Red Hat Enterprise Linux 5 RedHat avahi-0:0.6.16-10.el5_6 *
Red Hat Enterprise Linux 6 RedHat avahi-0:0.6.25-11.el6 *
Avahi Ubuntu dapper *
Avahi Ubuntu hardy *
Avahi Ubuntu karmic *
Avahi Ubuntu lucid *
Avahi Ubuntu maverick *
Avahi Ubuntu upstream *

References