CVE-2011-1002: Medium severity avahi autoip daemon vulnerability
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2011-1002?
CVE-2011-1002 has a high severity level as it allows remote attackers to cause a denial of service through an infinite loop.
How do I fix CVE-2011-1002?
To fix CVE-2011-1002, upgrade to a version of Avahi that is at least 0.6.29 or higher.
Which versions of Avahi are affected by CVE-2011-1002?
CVE-2011-1002 affects multiple versions of Avahi, including but not limited to 0.6.25, 0.6.5, and 0.6.27.
What type of vulnerability is CVE-2011-1002?
CVE-2011-1002 is a denial of service vulnerability that can be exploited via empty mDNS UDP packets.
What is the impact of exploiting CVE-2011-1002?
Exploiting CVE-2011-1002 can cause the Avahi daemon to enter an infinite loop, effectively disabling its mDNS services.