FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-2244

This CVE name corresponds to:

Entered Topic
2011-03-13 avahi -- denial of service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-2244
Phase Assigned(20100609)

Description

The AvahiDnsPacket function in avahi-core/socket.c in avahi-daemon in Avahi 0.6.16 and 0.6.25 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNS packet with an invalid checksum followed by a DNS packet with a valid checksum, a different vulnerability than CVE-2008-5081.

References

Source Reference
MLIST [oss-security] 20100623 CVE Request: avahi DoS
MLIST [oss-security] 20100625 Re: CVE Request: avahi DoS
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=607293
DEBIAN DSA-2086
FEDORA FEDORA-2010-10581
FEDORA FEDORA-2010-10584
MANDRIVA MDVSA-2010:204
SECTRACK 1024200