CVE-2006-5461
published 2006-11-14CVE-2006-5461: Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.40%
31.9th percentile
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | <= 0.6.14 | — |
| avahi | avahi | >= 0 < 0.6.15-1 | 0.6.15-1 |
| avahi | avahi | >= 0 < 0.6.15-1 | 0.6.15-1 |
| avahi | avahi | >= 0 < 0.6.15-1 | 0.6.15-1 |
| avahi | avahi | >= 0 < 0.6.15-1 | 0.6.15-1 |
| debian | avahi | < avahi 0.6.15-1 (bookworm) | avahi 0.6.15-1 (bookworm) |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Avahi vulnerability
vendor_ubuntu·2006-11-11
CVE-2006-5461 Avahi vulnerability
Title: Avahi vulnerability
Summary: Avahi vulnerability
Steve Grubb discovered that netlink messages were not being checked for
their sender identity. This could lead to local users manipulating the
Avahi service.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-5461: avahi - Avahi before 0.6.15 does not verify the sender identity of netlink messages to e...
vendor_debian·2006·CVSS 2.1
CVE-2006-5461 [LOW] CVE-2006-5461: avahi - Avahi before 0.6.15 does not verify the sender identity of netlink messages to e...
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
Scope: local
bookworm: resolved (fixed in 0.6.15-1)
bullseye: resolved (fixed in 0.6.15-1)
forky: resolved (fixed in 0.6.15-1)
sid: resolved (fixed in 0.6.15-1)
trixie: resolved (fixed in 0.6.15-1)
GHSA
GHSA-4w5j-fgfj-644h: Avahi before 0
ghsa_unreviewed·2022-05-01
CVE-2006-5461 [LOW] GHSA-4w5j-fgfj-644h: Avahi before 0
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
OSV
CVE-2006-5461: Avahi before 0
osv·2006-11-14·CVSS 2.1
CVE-2006-5461 [LOW] CVE-2006-5461: Avahi before 0
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://avahi.org/milestone/Avahi%200.6.15http://secunia.com/advisories/22807http://secunia.com/advisories/22852http://secunia.com/advisories/22932http://secunia.com/advisories/23020http://secunia.com/advisories/23042http://securitytracker.com/id?1017257http://www.gentoo.org/security/en/glsa/glsa-200611-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:215http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.securityfocus.com/bid/21016http://www.vupen.com/english/advisories/2006/4474https://exchange.xforce.ibmcloud.com/vulnerabilities/30207https://tango.0pointer.de/pipermail/avahi-tickets/2006-November/000320.htmlhttps://usn.ubuntu.com/380-1/http://avahi.org/milestone/Avahi%200.6.15http://secunia.com/advisories/22807http://secunia.com/advisories/22852http://secunia.com/advisories/22932http://secunia.com/advisories/23020http://secunia.com/advisories/23042http://securitytracker.com/id?1017257http://www.gentoo.org/security/en/glsa/glsa-200611-13.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:215http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.securityfocus.com/bid/21016http://www.vupen.com/english/advisories/2006/4474https://exchange.xforce.ibmcloud.com/vulnerabilities/30207https://tango.0pointer.de/pipermail/avahi-tickets/2006-November/000320.htmlhttps://usn.ubuntu.com/380-1/
2006-11-14
Published