CVE-2009-0758: High severity Avahi avahi-daemon vulnerability
The originatesfromlocallegacyunicastsocket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0758?
CVE-2009-0758 is classified as a denial of service vulnerability.
How do I fix CVE-2009-0758?
To fix CVE-2009-0758, upgrade to a version of avahi-daemon that addresses this vulnerability.
What type of vulnerability is CVE-2009-0758?
CVE-2009-0758 is a denial of service vulnerability affecting avahi-daemon.
Which version of avahi-daemon is affected by CVE-2009-0758?
CVE-2009-0758 specifically affects avahi-daemon version 0.6.23.
Can CVE-2009-0758 be exploited remotely?
Yes, CVE-2009-0758 can be exploited remotely by attackers to disrupt service.