CVE DATABASE / CVE-2011-1002
CVE-2011-1002
CVSS 5 · MEDIUM
Summary
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.
CVSS 2.0 breakdown
| Base score | 5 (MEDIUM) |
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Confidentiality | NONE |
| Integrity | NONE |
| Availability | PARTIAL |
Weakness type (CWE)
Affected products
Avahi avahiFedoraproject fedoraRedhat enterprise linuxCanonical ubuntu linuxDebian debian linux
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://avahi.org/ticket/325
- http://git.0pointer.de/?p=avahi.git%3Ba=commit%3Bh=46109dfec75534fe270c0ab902576f685d5ab3a6
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055858.html
- http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html
- http://openwall.com/lists/oss-security/2011/02/18/1
- http://openwall.com/lists/oss-security/2011/02/18/4
- http://osvdb.org/70948
- http://secunia.com/advisories/43361
- http://secunia.com/advisories/43465
- http://secunia.com/advisories/43605
- http://secunia.com/advisories/43673
- http://secunia.com/advisories/44131
- http://ubuntu.com/usn/usn-1084-1
- http://www.debian.org/security/2011/dsa-2174
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:037
Data: NIST NVD. NVD last modified 2026-04-29. Always verify against the vendor advisory before acting.