Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade avahi | Jul 30, 2024 | Nov 14, 2006 |
| Gentoo Linux | — | Upgrade net-dns/avahi. | Oct 30, 2017 | Nov 14, 2006 |
| Suse | — | Upgrade libavahi-ui-gtk3-0Upgrade libavahi-core7Upgrade libavahi-glib1Upgrade avahi-compat-mDNSResponder-develUpgrade python-avahiUpgrade python3-avahi-gtkUpgrade libavahi-core5Upgrade libavahi-client3-32bitUpgrade avahiUpgrade libavahi-common3-x86Upgrade avahi-utils-gtkUpgrade typelib-1_0-Avahi-0_6Upgrade libdns_sd-32bitUpgrade libavahi-glib-develUpgrade libavahi-libevent1Upgrade libavahi-client3Upgrade libavahi-common3Upgrade libavahi-client3-x86Upgrade libavahi-gobject0Upgrade avahi-utilsUpgrade libavahi-develUpgrade libdns_sd-x86Upgrade libavahi-common3-32bitUpgrade avahi-autoipdUpgrade avahi-compat-howl-develUpgrade libdns_sdUpgrade avahi-langUpgrade libavahi-gobject-develUpgrade python313-avahiUpgrade libhowl0 | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libavahi-core1Upgrade avahi-daemonUpgrade libavahi-core4 | Nov 8, 2024 | Nov 14, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub