CVE-2009-0758
Publication date 3 March 2009
Last updated 24 July 2024
Ubuntu priority
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
Status
Package | Ubuntu Release | Status |
---|---|---|
avahi | 10.04 LTS lucid |
Not affected
|
9.10 karmic |
Not affected
|
|
9.04 jaunty |
Fixed 0.6.23-4ubuntu4.1
|
|
8.10 intrepid | Ignored end of life, was needed | |
8.04 LTS hardy |
Fixed 0.6.22-2ubuntu4.2
|
|
7.10 gutsy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |
Notes
Patch details
Package | Patch details |
---|---|
avahi |