Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-26720: Debian -- Details of package avahi-daemon in buster

avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.

CVE
#mac#linux#debian#dos

Package: avahi-daemon (0.7-4+deb10u1)

Avahi mDNS/DNS-SD daemon

Avahi is a fully LGPL framework for Multicast DNS Service Discovery. It allows programs to publish and discover services and hosts running on a local network with no specific configuration. For example you can plug into a network and instantly find printers to print to, files to look at and people to talk to.

This package contains the Avahi Daemon which represents your machine on the network and allows other applications to publish and resolve mDNS/DNS-SD records.

Tags: Implemented in: C, User Interface: Daemon, Networking: network::configuration, network::scanner, Server, Network Protocol: DNS, protocol::zeroconf, role::program, Scope: Utility, Purpose: Scanning

Other Packages Related to avahi-daemon

  • depends

  • recommends

  • suggests

  • enhances

  • dep: adduser

    add and remove users and groups

  • dep: bind9-host

    DNS lookup utility (deprecated)

    or host

    virtual package provided by bind9-host

  • dep: dbus (>= 0.60)

    simple interprocess messaging system (daemon and utilities)

  • dep: libavahi-common3 (>= 0.6.16)

    Avahi common library

  • dep: libavahi-core7 (>= 0.6.24)

    Avahi’s embeddable mDNS/DNS-SD library

  • dep: libc6 (>= 2.27) [amd64, arm64, mips64el, ppc64el, s390x]

    GNU C Library: Shared libraries
    also a virtual package provided by libc6-udeb

    dep: libc6 (>= 2.28) [armel, armhf, i386, mips, mipsel]

  • dep: libcap2 (>= 1:2.10)

    POSIX 1003.1e capabilities (library)

  • dep: libdaemon0 (>= 0.14)

    lightweight C library for daemons - runtime library

  • dep: libdbus-1-3 (>= 1.9.14)

    simple interprocess messaging system (library)

  • dep: libexpat1 (>= 2.0.1)

    XML parsing C library - runtime library

  • dep: lsb-base (>= 3.0-6)

    Linux Standard Base init script functionality

  • rec: libnss-mdns (>= 0.11)

    NSS module for Multicast DNS name resolution

  • sug: avahi-autoipd

    Avahi IPv4LL network address configuration daemon

Related news

CVE-2023-43074: DSA-2023-141: Dell Unity, Unity VSA and Unity XT Security Update for Multiple Vulnerability

Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907