Headline
CVE-2021-26720: Debian -- Details of package avahi-daemon in buster
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
Package: avahi-daemon (0.7-4+deb10u1)
Avahi mDNS/DNS-SD daemon
Avahi is a fully LGPL framework for Multicast DNS Service Discovery. It allows programs to publish and discover services and hosts running on a local network with no specific configuration. For example you can plug into a network and instantly find printers to print to, files to look at and people to talk to.
This package contains the Avahi Daemon which represents your machine on the network and allows other applications to publish and resolve mDNS/DNS-SD records.
Tags: Implemented in: C, User Interface: Daemon, Networking: network::configuration, network::scanner, Server, Network Protocol: DNS, protocol::zeroconf, role::program, Scope: Utility, Purpose: Scanning
Other Packages Related to avahi-daemon
depends
recommends
suggests
enhances
dep: adduser
add and remove users and groups
dep: bind9-host
DNS lookup utility (deprecated)
or host
virtual package provided by bind9-host
dep: dbus (>= 0.60)
simple interprocess messaging system (daemon and utilities)
dep: libavahi-common3 (>= 0.6.16)
Avahi common library
dep: libavahi-core7 (>= 0.6.24)
Avahi’s embeddable mDNS/DNS-SD library
dep: libc6 (>= 2.27) [amd64, arm64, mips64el, ppc64el, s390x]
GNU C Library: Shared libraries
also a virtual package provided by libc6-udebdep: libc6 (>= 2.28) [armel, armhf, i386, mips, mipsel]
dep: libcap2 (>= 1:2.10)
POSIX 1003.1e capabilities (library)
dep: libdaemon0 (>= 0.14)
lightweight C library for daemons - runtime library
dep: libdbus-1-3 (>= 1.9.14)
simple interprocess messaging system (library)
dep: libexpat1 (>= 2.0.1)
XML parsing C library - runtime library
dep: lsb-base (>= 3.0-6)
Linux Standard Base init script functionality
rec: libnss-mdns (>= 0.11)
NSS module for Multicast DNS name resolution
sug: avahi-autoipd
Avahi IPv4LL network address configuration daemon
Related news
Dell Unity 5.3 contain(s) an Arbitrary File Creation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by crafting arbitrary files through a request to the server.