CVE-2006-6870: Medium severity Avahi Avahi vulnerability
Published Dec 31, 2006
·Updated
The consumelabels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.
Affected Software
9 affected components
Avahi Avahi=0.6.7
Avahi Avahi=0.6.8
Avahi Avahi=0.6.9
Avahi Avahi=0.6.10
Avahi Avahi=0.6.11
Avahi Avahi=0.6.12
Avahi Avahi=0.6.13
Avahi Avahi=0.6.14
Avahi Avahi=0.6.15
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2006
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Jan 5, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6870?
CVE-2006-6870 is classified as a denial of service vulnerability due to an infinite loop caused by a crafted DNS response.
2
How do I fix CVE-2006-6870?
To mitigate CVE-2006-6870, upgrade to Avahi version 0.6.16 or later.
3
Which versions are affected by CVE-2006-6870?
CVE-2006-6870 affects Avahi versions 0.6.7 through 0.6.15.
4
What is the impact of CVE-2006-6870?
The impact of CVE-2006-6870 is a denial of service that can cause the affected service to become unresponsive.
5
Can CVE-2006-6870 be exploited remotely?
Yes, CVE-2006-6870 can be exploited remotely via a specially crafted DNS response.