avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade avahi | Mar 26, 2024 | Feb 17, 2021 |
| Debian | — | Upgrade avahi | Jun 9, 2022 | Feb 17, 2021 |
| Suse | — | Upgrade libavahi-client3Upgrade avahi-compat-mdnsresponder-develUpgrade libavahi-glib1-32bitUpgrade python3-avahiUpgrade libavahi-common3Upgrade avahi-compat-howl-develUpgrade libavahi-glib-develUpgrade avahi-utils-gtkUpgrade avahi-autoipdUpgrade libavahi-qt4-1Upgrade avahi-langUpgrade libavahi-common3-32bitUpgrade libavahi-client3-32bitUpgrade libdns_sd-32bitUpgrade avahi-monoUpgrade python-avahi-gtkUpgrade libavahi-qt4-develUpgrade libavahi-develUpgrade libavahi-libevent1Upgrade libavahi-ui-gtk3-0Upgrade libhowl0Upgrade libdns_sdUpgrade libavahi-gobject0Upgrade libavahi-gobject-develUpgrade libavahi-ui0Upgrade python-avahiUpgrade libavahi-glib1Upgrade libavahi-core7Upgrade python3-avahi-gtkUpgrade avahiUpgrade avahi-utilsUpgrade typelib-1_0-avahi-0_6 | Feb 24, 2021 | Feb 17, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub