CVE-2011-1002

Publication date 22 February 2011

Last updated 24 July 2024


Ubuntu priority

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.

Status

Package Ubuntu Release Status
avahi 10.10 maverick
Fixed 0.6.27-2ubuntu3.1
10.04 LTS lucid
Fixed 0.6.25-1ubuntu6.2
9.10 karmic
Fixed 0.6.25-1ubuntu5.3
8.04 LTS hardy
Fixed 0.6.22-2ubuntu4.3
6.06 LTS dapper Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
avahi