CVE-2009-0758

NameCVE-2009-0758
DescriptionThe originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of a port number when processing incoming multicast packets, which allows remote attackers to cause a denial of service (network bandwidth and CPU consumption) via a crafted legacy unicast mDNS query packet that triggers a multicast packet storm.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2086-1
Debian Bugs517683

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
avahi (PTS)jessie, jessie (lts)0.6.31-5+deb8u2fixed
stretch (security)0.6.32-2+deb9u1fixed
stretch (lts), stretch0.6.32-2+deb9u2fixed
buster (security), buster, buster (lts)0.7-4+deb10u3fixed
bullseye0.8-5+deb11u2fixed
bookworm0.8-10fixed
sid, trixie0.8-13fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
avahisourcelenny0.6.23-3lenny2DSA-2086-1
avahisource(unstable)0.6.24-3low517683

Notes

[etch] - avahi <no-dsa> (Minor issue)
reflector is off by default

Search for package or bug name: Reporting problems