Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-52615

Опубликовано: 21 нояб. 2024
Источник: debian

Описание

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
avahiunfixedpackage
avahino-dsatrixiepackage
avahino-dsabookwormpackage
avahipostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2326418

  • https://github.com/avahi/avahi/issues/254

  • https://github.com/avahi/avahi/issues/254#issuecomment-2480519212

  • turn off wide-area feature: https://github.com/avahi/avahi/pull/577

  • Revisiting of feature: https://github.com/avahi/avahi/issues/578

  • https://github.com/avahi/avahi/security/advisories/GHSA-x6vp-f33h-h32g

  • https://github.com/avahi/avahi/pull/662

  • Fixed by: https://github.com/avahi/avahi/commit/4e2e1ea0908d7e6ad7f38ae04fdcdf2411f8b942

Связанные уязвимости

CVSS3: 5.3
ubuntu
9 месяцев назад

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

CVSS3: 5.3
redhat
9 месяцев назад

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

CVSS3: 5.3
nvd
9 месяцев назад

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

oracle-oval
22 дня назад

ELSA-2025-11402: avahi security update (MODERATE)