The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade avahi-develUpgrade avahi-compat-libdns_sd-develUpgrade avahi-compat-libdns_sdUpgrade avahi-toolsUpgrade avahi-glib-develUpgrade avahiUpgrade avahi-glibUpgrade avahi-qt3Upgrade avahi-compat-howl-develUpgrade avahi-qt3-develUpgrade avahi-compat-howl | Dec 1, 2016 | Dec 16, 2008 |
| Debian | — | Upgrade avahi | Jul 30, 2024 | Dec 17, 2008 |
| Gentoo Linux | — | Upgrade net-dns/avahi. | Oct 30, 2017 | Dec 16, 2008 |
| Oracle_linux | — | Upgrade avahi-compat-howl-develUpgrade avahi-qt3-develUpgrade avahi-qt3Upgrade avahi-toolsUpgrade avahi-compat-libdns_sdUpgrade avahi-develUpgrade avahi-glib-develUpgrade avahi-compat-libdns_sd-develUpgrade avahi-compat-howlUpgrade avahiUpgrade avahi-glib | Oct 16, 2024 | Dec 17, 2008 |
| Suse | — | Upgrade typelib-1_0-Avahi-0_6Upgrade libavahi-client3Upgrade libdns_sd-32bitUpgrade libavahi-libevent1Upgrade avahi-langUpgrade avahi-compat-howl-develUpgrade python-avahiUpgrade python3-avahi-gtkUpgrade libavahi-gobject-develUpgrade libavahi-client3-32bitUpgrade libavahi-common3-32bitUpgrade libavahi-qt6-develUpgrade avahi-compat-mDNSResponder-develUpgrade libavahi-common3Upgrade libavahi-client3-x86Upgrade libavahi-ui-gtk3-0Upgrade avahiUpgrade libavahi-gobject0Upgrade libhowl0Upgrade libdns_sd-x86Upgrade libdns_sdUpgrade libavahi-develUpgrade python313-avahiUpgrade avahi-utilsUpgrade avahi-utils-gtkUpgrade libavahi-core5Upgrade libavahi-core7Upgrade avahi-autoipdUpgrade libavahi-common3-x86Upgrade libavahi-glib1Upgrade libavahi-qt6-1Upgrade libavahi-glib-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade avahi-daemon | Nov 8, 2024 | Dec 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub