PT-2011-1132 · Avahi+1 · Avahi-Qt3-Devel+11

Nuh

·

Published

2011-02-22

·

Updated

2025-09-26

·

CVE-2011-1002

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions avahi versions prior to 0.6.29 avahi-glib versions 0.6.16 avahi-glib-devel versions 0.6.16 avahi-compat-howl versions 0.6.16 avahi-compat-howl-devel versions 0.6.16 avahi-qt3 versions 0.6.16 avahi-qt3-devel versions 0.6.16 avahi-devel versions 0.6.16 avahi-tools versions 0.6.16 avahi-compat-libdns sd versions 0.6.16 avahi-compat-libdns sd-devel versions 0.6.16
Description The issue allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. This can lead to disruption of protected information availability. The vulnerability can be exploited remotely.
Recommendations For avahi versions prior to 0.6.29, update to version 0.6.29 or later. For avahi-glib versions 0.6.16, update to a version later than 0.6.16. For avahi-glib-devel versions 0.6.16, update to a version later than 0.6.16. For avahi-compat-howl versions 0.6.16, update to a version later than 0.6.16. For avahi-compat-howl-devel versions 0.6.16, update to a version later than 0.6.16. For avahi-qt3 versions 0.6.16, update to a version later than 0.6.16. For avahi-qt3-devel versions 0.6.16, update to a version later than 0.6.16. For avahi-devel versions 0.6.16, update to a version later than 0.6.16. For avahi-tools versions 0.6.16, update to a version later than 0.6.16. For avahi-compat-libdns sd versions 0.6.16, update to a version later than 0.6.16. For avahi-compat-libdns sd-devel versions 0.6.16, update to a version later than 0.6.16.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-06969
BDU:2015-06970
BDU:2015-06971
BDU:2015-06972
BDU:2015-06973
BDU:2015-06974
BDU:2015-06975
BDU:2015-06976
BDU:2015-06977
BDU:2015-06978
BDU:2015-06979
BDU:2015-08705
BDU:2015-08706
BDU:2015-08707
BDU:2015-08708
BDU:2015-08709
BDU:2015-08710
BDU:2015-08711
BDU:2015-08712
BDU:2015-08713
BDU:2015-08714
BDU:2015-08715
BDU:2015-09419
CVE-2011-1002
DSA-2174-1
ELSA-2011-0779
OPENSUSE-SU-2024:10363-1
RHSA-2011:0436
RHSA-2011:0779
RHSA-2011_0436
RHSA-2011_0779

Affected Products

Red Hat
Avahi
Avahi-Compat-Howl
Avahi-Compat-Howl-Devel
Avahi-Compat-Libdns Sd
Avahi-Compat-Libdns Sd-Devel
Avahi-Devel
Avahi-Glib
Avahi-Glib-Devel
Avahi-Qt3
Avahi-Qt3-Devel
Avahi-Tools