avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade avahi | Mar 26, 2024 | Feb 17, 2021 |
| Debian | — | Upgrade avahi | Jun 9, 2022 | Feb 17, 2021 |
| Suse | — | Upgrade libavahi-common3Upgrade libavahi-common3-32bitUpgrade python3-avahiUpgrade typelib-1_0-Avahi-0_6Upgrade avahi-autoipdUpgrade libavahi-qt4-1Upgrade avahi-utils-gtkUpgrade libdns_sd-32bitUpgrade libavahi-client3Upgrade avahi-compat-mDNSResponder-develUpgrade avahi-langUpgrade libavahi-client3-32bitUpgrade avahi-compat-howl-develUpgrade libavahi-glib1-32bitUpgrade libavahi-glib-develUpgrade python-avahi-gtkUpgrade libavahi-glib1Upgrade avahi-monoUpgrade libavahi-gobject-develUpgrade python3-avahi-gtkUpgrade libdns_sdUpgrade libavahi-develUpgrade libavahi-gobject0Upgrade avahiUpgrade libavahi-ui0Upgrade avahi-utilsUpgrade libavahi-core7Upgrade libavahi-libevent1Upgrade python-avahiUpgrade libhowl0Upgrade libavahi-ui-gtk3-0Upgrade libavahi-qt4-devel | Feb 24, 2021 | Feb 17, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Feb 17, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub