CVE-2008-5081

Avahi < 0.6.23 - Resource Management Error

Title source: rule

Description

The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Jon Oberheide · cdosmultiple
https://www.exploit-db.com/exploits/7520
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/mdns/avahi_portzero.rb

Scores

EPSS 0.7708
EPSS Percentile 99.0%

Details

CWE
CWE-399
Status published
Products (30)
avahi/avahi 0.1
avahi/avahi 0.2
avahi/avahi 0.3
avahi/avahi 0.4
avahi/avahi 0.5
avahi/avahi 0.5.1
avahi/avahi 0.5.2
avahi/avahi 0.6.1
avahi/avahi 0.6.2
avahi/avahi 0.6.3
... and 20 more
Published Dec 17, 2008
Tracked Since Feb 18, 2026