CVE-2008-5081

Publication date 17 December 2008

Last updated 24 July 2024


Ubuntu priority

The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.

Status

Package Ubuntu Release Status
avahi 8.10 intrepid
Fixed 0.6.23-2ubuntu2.1
8.04 LTS hardy
Fixed 0.6.22-2ubuntu4.1
7.10 gutsy
Fixed 0.6.20-2ubuntu3.4
6.06 LTS dapper
Fixed 0.6.10-0ubuntu3.5

References

Related Ubuntu Security Notices (USN)

    • USN-696-1
    • Avahi vulnerabilities
    • 18 December 2008

Other references