LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2011-1002

CVE-2011-1002

CVSS 5 · MEDIUM

Summary

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.

CVSS 2.0 breakdown

Base score5 (MEDIUM)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityNONE
IntegrityNONE
AvailabilityPARTIAL

Weakness type (CWE)

Affected products

Avahi avahiFedoraproject fedoraRedhat enterprise linuxCanonical ubuntu linuxDebian debian linux
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-29. Always verify against the vendor advisory before acting.

Scroll to Top