avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade avahi | Mar 26, 2024 | Feb 17, 2021 |
| Debian | — | Upgrade avahi | Jun 9, 2022 | Feb 17, 2021 |
| Suse | — | Upgrade avahi-compat-mDNSResponder-develUpgrade libavahi-qt4-1Upgrade typelib-1_0-Avahi-0_6Upgrade python3-avahiUpgrade libavahi-client3Upgrade libavahi-common3-32bitUpgrade avahi-autoipdUpgrade libavahi-glib1-32bitUpgrade libavahi-client3-32bitUpgrade avahi-utils-gtkUpgrade avahi-langUpgrade libavahi-common3Upgrade libdns_sd-32bitUpgrade avahi-compat-howl-develUpgrade libavahi-glib-develUpgrade libavahi-gobject-develUpgrade avahi-utilsUpgrade python3-avahi-gtkUpgrade libavahi-ui-gtk3-0Upgrade libdns_sdUpgrade python-avahiUpgrade libhowl0Upgrade python-avahi-gtkUpgrade avahi-monoUpgrade libavahi-qt4-develUpgrade libavahi-glib1Upgrade libavahi-develUpgrade libavahi-core7Upgrade avahiUpgrade libavahi-libevent1Upgrade libavahi-ui0Upgrade libavahi-gobject0 | Feb 24, 2021 | Feb 17, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub