MEDIUM
The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself
Published Jan 5, 2007
5.0
MEDIUMCVSS 2.0
EPSS 2.44%
Description
The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (17)
- http://fedoranews.org/cms/node/2362 vendor-advisoryx_refsource_FEDORA
- http://fedoranews.org/cms/node/2408 vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/23628 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23644 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23660 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23673 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/23782 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/24995 third-party-advisoryx_refsource_SECUNIA
- http://www.avahi.org/#December2006 x_refsource_CONFIRMPatch
- http://www.avahi.org/changeset/1340 x_refsource_CONFIRM
- http://www.avahi.org/ticket/84 x_refsource_CONFIRMPatch
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:003 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_007_suse.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/21881 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/usn-402-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2007/0071 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-6853 Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Jan 5, 2007
Updated Aug 7, 2024
Reserved Jan 4, 2007
Link CVE-2006-6870
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-6853 Assigner canonical
Published Jan 5, 2007
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-6853