Lucene search

K
ubuntuUbuntuUSN-402-1
HistoryJan 05, 2007 - 12:00 a.m.

Avahi vulnerability

2007-01-0500:00:00
ubuntu.com
34

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.12

Percentile

95.4%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06
  • Ubuntu 5.10

Details

A flaw was discovered in Avahi’s handling of compressed DNS packets. If
a specially crafted reply were received over the network, the Avahi
daemon would go into an infinite loop, causing a denial of service.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchavahi-daemon< 0.6.13-2ubuntu2.4UNKNOWN
Ubuntu6.06noarchavahi-daemon< 0.6.10-0ubuntu3.4UNKNOWN
Ubuntu5.10noarchavahi-daemon< 0.5.2-1ubuntu1.4UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.2

Confidence

Low

EPSS

0.12

Percentile

95.4%