Avahi contains a flaw that may allow a remote denial of service. The issue is triggered when 'avahi-core/socket.c' in 'avahi-daemon' fails to properly handle empty IPv4 or IPv6 UDP packets sent to port 5353, allowing a remote attacker to cause an infinite loop which will trigger a denial of service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Solution:
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Avahi has committed a source code patch to address this vulnerability which is slated to be included in version 0.6.29.