CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:N/I:N/A:P
AI Score
Confidence
High
EPSS
Percentile
95.4%
The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.
Vendor | Product | Version | CPE |
---|---|---|---|
avahi | avahi | 0.6.7 | cpe:2.3:a:avahi:avahi:0.6.7:*:*:*:*:*:*:* |
avahi | avahi | 0.6.8 | cpe:2.3:a:avahi:avahi:0.6.8:*:*:*:*:*:*:* |
avahi | avahi | 0.6.9 | cpe:2.3:a:avahi:avahi:0.6.9:*:*:*:*:*:*:* |
avahi | avahi | 0.6.10 | cpe:2.3:a:avahi:avahi:0.6.10:*:*:*:*:*:*:* |
avahi | avahi | 0.6.11 | cpe:2.3:a:avahi:avahi:0.6.11:*:*:*:*:*:*:* |
avahi | avahi | 0.6.12 | cpe:2.3:a:avahi:avahi:0.6.12:*:*:*:*:*:*:* |
avahi | avahi | 0.6.13 | cpe:2.3:a:avahi:avahi:0.6.13:*:*:*:*:*:*:* |
avahi | avahi | 0.6.14 | cpe:2.3:a:avahi:avahi:0.6.14:*:*:*:*:*:*:* |
avahi | avahi | 0.6.15 | cpe:2.3:a:avahi:avahi:0.6.15:*:*:*:*:*:*:* |
fedoranews.org/cms/node/2362
fedoranews.org/cms/node/2408
secunia.com/advisories/23628
secunia.com/advisories/23644
secunia.com/advisories/23660
secunia.com/advisories/23673
secunia.com/advisories/23782
secunia.com/advisories/24995
www.avahi.org/#December2006
www.avahi.org/changeset/1340
www.avahi.org/ticket/84
www.mandriva.com/security/advisories?name=MDKSA-2007:003
www.novell.com/linux/security/advisories/2007_007_suse.html
www.securityfocus.com/bid/21881
www.ubuntu.com/usn/usn-402-1
www.vupen.com/english/advisories/2007/0071