avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade avahi | Mar 26, 2024 | Feb 17, 2021 |
| Debian | — | Upgrade avahi | Jun 9, 2022 | Feb 17, 2021 |
| Suse | — | Upgrade libavahi-qt4-1Upgrade libdns_sd-32bitUpgrade avahi-compat-mdnsresponder-develUpgrade libavahi-glib1-32bitUpgrade libavahi-glib-develUpgrade avahi-langUpgrade avahi-compat-howl-develUpgrade python3-avahiUpgrade libavahi-client3Upgrade libavahi-common3-32bitUpgrade libavahi-client3-32bitUpgrade libavahi-common3Upgrade avahi-utils-gtkUpgrade avahi-autoipdUpgrade avahiUpgrade libavahi-ui0Upgrade typelib-1_0-avahi-0_6Upgrade python3-avahi-gtkUpgrade libdns_sdUpgrade libavahi-libevent1Upgrade libavahi-gobject-develUpgrade libavahi-glib1Upgrade libhowl0Upgrade python-avahiUpgrade libavahi-ui-gtk3-0Upgrade libavahi-gobject0Upgrade libavahi-core7Upgrade libavahi-qt4-develUpgrade python-avahi-gtkUpgrade avahi-monoUpgrade avahi-utilsUpgrade libavahi-devel | Feb 24, 2021 | Feb 17, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub