CVE-2010-2244: Medium severity avahi autoip daemon vulnerability
Ludwig Nussel reported: [1] http://www.openwall.com/lists/oss-security/2010/06/23/4
a deficiency in the way avahi daemon processed packets with corrupted checksum(s). A remote attacker on the same local are network (LAN) could send a DNS packet with broken checksum, that would cause avahi-daemon to exit unexpectedly due to a failed assertion check. Different vulnerability than CVE-2008-5081.
Other sources
The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2244?
CVE-2010-2244 is classified as a low severity vulnerability.
How do I fix CVE-2010-2244?
To fix CVE-2010-2244, upgrade to avahi version 0.6.25 or later.
Who discovered CVE-2010-2244?
CVE-2010-2244 was reported by Ludwig Nussel.
What type of attack does CVE-2010-2244 enable?
CVE-2010-2244 allows remote attackers on the same local area network to exploit vulnerabilities in packet processing.
Which software versions are affected by CVE-2010-2244?
CVE-2010-2244 affects avahi versions 0.6.16 through 0.6.24.