avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avahi | Avahi | * | 0.6.28 (including) |
Avahi | Avahi | 0.1 (including) | 0.1 (including) |
Avahi | Avahi | 0.2 (including) | 0.2 (including) |
Avahi | Avahi | 0.3 (including) | 0.3 (including) |
Avahi | Avahi | 0.4 (including) | 0.4 (including) |
Avahi | Avahi | 0.5 (including) | 0.5 (including) |
Avahi | Avahi | 0.5.1 (including) | 0.5.1 (including) |
Avahi | Avahi | 0.5.2 (including) | 0.5.2 (including) |
Avahi | Avahi | 0.6.1 (including) | 0.6.1 (including) |
Avahi | Avahi | 0.6.2 (including) | 0.6.2 (including) |
Avahi | Avahi | 0.6.3 (including) | 0.6.3 (including) |
Avahi | Avahi | 0.6.4 (including) | 0.6.4 (including) |
Avahi | Avahi | 0.6.5 (including) | 0.6.5 (including) |
Avahi | Avahi | 0.6.6 (including) | 0.6.6 (including) |
Avahi | Avahi | 0.6.7 (including) | 0.6.7 (including) |
Avahi | Avahi | 0.6.8 (including) | 0.6.8 (including) |
Avahi | Avahi | 0.6.9 (including) | 0.6.9 (including) |
Avahi | Avahi | 0.6.10 (including) | 0.6.10 (including) |
Avahi | Avahi | 0.6.11 (including) | 0.6.11 (including) |
Avahi | Avahi | 0.6.12 (including) | 0.6.12 (including) |
Avahi | Avahi | 0.6.13 (including) | 0.6.13 (including) |
Avahi | Avahi | 0.6.14 (including) | 0.6.14 (including) |
Avahi | Avahi | 0.6.15 (including) | 0.6.15 (including) |
Avahi | Avahi | 0.6.16 (including) | 0.6.16 (including) |
Avahi | Avahi | 0.6.17 (including) | 0.6.17 (including) |
Avahi | Avahi | 0.6.18 (including) | 0.6.18 (including) |
Avahi | Avahi | 0.6.19 (including) | 0.6.19 (including) |
Avahi | Avahi | 0.6.20 (including) | 0.6.20 (including) |
Avahi | Avahi | 0.6.21 (including) | 0.6.21 (including) |
Avahi | Avahi | 0.6.22 (including) | 0.6.22 (including) |
Avahi | Avahi | 0.6.23 (including) | 0.6.23 (including) |
Avahi | Avahi | 0.6.24 (including) | 0.6.24 (including) |
Avahi | Avahi | 0.6.25 (including) | 0.6.25 (including) |
Avahi | Avahi | 0.6.26 (including) | 0.6.26 (including) |
Avahi | Avahi | 0.6.27 (including) | 0.6.27 (including) |
Red Hat Enterprise Linux 5 | RedHat | avahi-0:0.6.16-10.el5_6 | * |
Red Hat Enterprise Linux 6 | RedHat | avahi-0:0.6.25-11.el6 | * |
Avahi | Ubuntu | dapper | * |
Avahi | Ubuntu | hardy | * |
Avahi | Ubuntu | karmic | * |
Avahi | Ubuntu | lucid | * |
Avahi | Ubuntu | maverick | * |
Avahi | Ubuntu | upstream | * |