avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade avahi | Mar 26, 2024 | Feb 17, 2021 |
| Debian | — | Upgrade avahi | Jun 9, 2022 | Feb 17, 2021 |
| Suse | — | Upgrade avahi-utils-gtkUpgrade avahi-autoipdUpgrade python3-avahiUpgrade libavahi-qt4-1Upgrade libdns_sd-32bitUpgrade avahi-compat-howl-develUpgrade libavahi-client3-32bitUpgrade typelib-1_0-Avahi-0_6Upgrade libavahi-glib-develUpgrade avahi-compat-mDNSResponder-develUpgrade avahi-langUpgrade libavahi-common3Upgrade libavahi-glib1-32bitUpgrade libavahi-common3-32bitUpgrade libavahi-client3Upgrade libavahi-libevent1Upgrade libavahi-gobject0Upgrade libavahi-ui-gtk3-0Upgrade libavahi-ui0Upgrade python3-avahi-gtkUpgrade libdns_sdUpgrade libavahi-gobject-develUpgrade libavahi-develUpgrade libavahi-qt4-develUpgrade avahiUpgrade libavahi-core7Upgrade avahi-utilsUpgrade avahi-monoUpgrade python-avahi-gtkUpgrade libavahi-glib1Upgrade python-avahiUpgrade libhowl0 | Feb 24, 2021 | Feb 17, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub