CVE-2009-0758
published 2009-03-03CVE-2009-0758: The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.01%
78.6th percentile
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | >= 0 < 0.6.24-3 | 0.6.24-3 |
| avahi | avahi | >= 0 < 0.6.24-3 | 0.6.24-3 |
| avahi | avahi | >= 0 < 0.6.24-3 | 0.6.24-3 |
| avahi | avahi | >= 0 < 0.6.24-3 | 0.6.24-3 |
| avahi | avahi-daemon | — | — |
| debian | avahi | < avahi 0.6.24-3 (bookworm) | avahi 0.6.24-3 (bookworm) |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Avahi vulnerabilities
vendor_ubuntu·2010-09-29·CVSS 7.8
CVE-2009-0758 [HIGH] Avahi vulnerabilities
Title: Avahi vulnerabilities
It was discovered that Avahi incorrectly handled certain mDNS query packets
when the reflector feature is enabled, which is not the default
configuration on Ubuntu. A remote attacker could send crafted mDNS queries
and perform a denial of service on the server and on the network. This
issue only affected Ubuntu 8.04 LTS and 9.04. (CVE-2009-0758)
It was discovered that Avahi incorrectly handled mDNS packets with
corrupted checksums. A remote attacker could send crafted mDNS packets and
cause Avahi to crash, resulting in a denial of service. (CVE-2010-2244)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
avahi: remote DoS via legacy unicast mDNS queries
vendor_redhat·2009-03-01·CVSS 7.8
CVE-2009-0758 [HIGH] avahi: remote DoS via legacy unicast mDNS queries
avahi: remote DoS via legacy unicast mDNS queries
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
Debian
CVE-2009-0758: avahi - The originates_from_local_legacy_unicast_socket function in avahi-core/server.c ...
vendor_debian·2009·CVSS 7.8
CVE-2009-0758 [HIGH] CVE-2009-0758: avahi - The originates_from_local_legacy_unicast_socket function in avahi-core/server.c ...
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
Scope: local
bookworm: resolved (fixed in 0.6.24-3)
bullseye: resolved (fixed in 0.6.24-3)
forky: resolved (fixed in 0.6.24-3)
sid: resolved (fixed in 0.6.24-3)
trixie: resolved (fixed in 0.6.24-3)
GHSA
GHSA-g7f8-4qm9-qgg5: The originates_from_local_legacy_unicast_socket function in avahi-core/server
ghsa_unreviewed·2022-05-02
CVE-2009-0758 [HIGH] GHSA-g7f8-4qm9-qgg5: The originates_from_local_legacy_unicast_socket function in avahi-core/server
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
OSV
CVE-2009-0758: The originates_from_local_legacy_unicast_socket function in avahi-core/server
osv·2009-03-03·CVSS 7.8
CVE-2009-0758 [HIGH] CVE-2009-0758: The originates_from_local_legacy_unicast_socket function in avahi-core/server
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517683http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.htmlhttp://secunia.com/advisories/38420http://www.debian.org/security/2010/dsa-2086http://www.mandriva.com/security/advisories?name=MDVSA-2009:076http://www.openwall.com/lists/oss-security/2009/03/02/1http://www.securityfocus.com/bid/33946http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=517683http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.htmlhttp://secunia.com/advisories/38420http://www.debian.org/security/2010/dsa-2086http://www.mandriva.com/security/advisories?name=MDVSA-2009:076http://www.openwall.com/lists/oss-security/2009/03/02/1http://www.securityfocus.com/bid/33946
2009-03-03
Published