Description
The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows remote attackers to cause a denial of service (infinite loop) via a crafted compressed DNS response with a label that points to itself.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9Complexity: Low
Confidentiality: None
Integrity: None
Affected Packages3 packages
🔴Vulnerability Details
2GHSAGHSA-mc78-8grw-5ghv: The consume_labels function in avahi-core/dns↗2022-05-01 ▶ OSVCVE-2006-6870: The consume_labels function in avahi-core/dns↗2006-12-31 ▶ 📋Vendor Advisories
2UbuntuAvahi vulnerability↗2007-01-05 ▶ DebianCVE-2006-6870: avahi - The consume_labels function in avahi-core/dns.c in Avahi before 0.6.16 allows re...↗2006 ▶ 📐Framework References
1CWEImproper Input Validation↗ ▶ 💬Community
4BugzillaCVE-2006-6870 Maliciously crafted packed can DoS avahi daemon↗2007-01-07 ▶ BugzillaCVE-2006-6870 Maliciously crafted packed can DoS avahi daemon↗2007-01-06 ▶ BugzillaCVE-2006-6870 Maliciously crafted packed can DoS avahi daemon↗2007-01-04 ▶ BugzillaCVE-2006-6870 Maliciously crafted packed can DoS avahi daemon↗2007-01-04 ▶