cbcvebase.
CVE-2009-0758
published 2009-03-03

CVE-2009-0758: The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port…

PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.01%
78.6th percentile
The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.

Affected

6 ranges
VendorProductVersion rangeFixed in
avahiavahi>= 0 < 0.6.24-30.6.24-3
avahiavahi>= 0 < 0.6.24-30.6.24-3
avahiavahi>= 0 < 0.6.24-30.6.24-3
avahiavahi>= 0 < 0.6.24-30.6.24-3
avahiavahi-daemon
debianavahi< avahi 0.6.24-3 (bookworm)avahi 0.6.24-3 (bookworm)

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.