CVE-2007-3372
published 2007-06-22CVE-2007-3372: The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.40%
32.8th percentile
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | <= 0.6.19 | — |
| avahi | avahi | >= 0 < 0.6.20-2 | 0.6.20-2 |
| avahi | avahi | >= 0 < 0.6.20-2 | 0.6.20-2 |
| avahi | avahi | >= 0 < 0.6.20-2 | 0.6.20-2 |
| avahi | avahi | >= 0 < 0.6.20-2 | 0.6.20-2 |
| debian | avahi | < avahi 0.6.20-2 (bookworm) | avahi 0.6.20-2 (bookworm) |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Avahi vulnerabilities
vendor_ubuntu·2008-12-18·CVSS 2.1
CVE-2007-3372 [LOW] Avahi vulnerabilities
Title: Avahi vulnerabilities
Summary: Avahi vulnerabilities
Emanuele Aina discovered that Avahi did not properly validate its input when
processing data over D-Bus. A local attacker could send an empty TXT message
via D-Bus and cause a denial of service (failed assertion). This issue only
affected Ubuntu 6.06 LTS. (CVE-2007-3372)
Hugo Dias discovered that Avahi did not properly verify its input when
processing mDNS packets. A remote attacker could send a crafted mDNS packet
and cause a denial of service (assertion failure). (CVE-2008-5081)
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
avahi: assert fail local DoS via D-Bus
vendor_redhat·2007-06-22·CVSS 2.1
CVE-2007-3372 [LOW] avahi: assert fail local DoS via D-Bus
avahi: assert fail local DoS via D-Bus
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
Statement: Not vulnerable. This issue did not affect the versions of avahi as shipped with Red Hat Enterprise Linux 5.
Debian
CVE-2007-3372: avahi - The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of se...
vendor_debian·2007·CVSS 2.1
CVE-2007-3372 [LOW] CVE-2007-3372: avahi - The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of se...
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
Scope: local
bookworm: resolved (fixed in 0.6.20-2)
bullseye: resolved (fixed in 0.6.20-2)
forky: resolved (fixed in 0.6.20-2)
sid: resolved (fixed in 0.6.20-2)
trixie: resolved (fixed in 0.6.20-2)
GHSA
GHSA-w53f-m8p6-x7g6: The Avahi daemon in Avahi before 0
ghsa_unreviewed·2022-05-01
CVE-2007-3372 [LOW] GHSA-w53f-m8p6-x7g6: The Avahi daemon in Avahi before 0
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
OSV
CVE-2007-3372: The Avahi daemon in Avahi before 0
osv·2007-06-22·CVSS 2.1
CVE-2007-3372 [LOW] CVE-2007-3372: The Avahi daemon in Avahi before 0
The Avahi daemon in Avahi before 0.6.20 allows attackers to cause a denial of service (exit) via empty TXT data over D-Bus, which triggers an assert error.
No detection rules found.
No public exploits indexed.
http://avahi.org/changeset/1482http://avahi.org/milestone/Avahi%200.6.20http://osvdb.org/37507http://secunia.com/advisories/25811http://secunia.com/advisories/26083http://secunia.com/advisories/26791http://secunia.com/advisories/33220http://secunia.com/advisories/33279http://www.debian.org/security/2008/dsa-1690http://www.mandriva.com/security/advisories?name=MDKSA-2007:185http://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.securityfocus.com/archive/1/472443/100/0/threadedhttp://www.securityfocus.com/bid/24614http://www.securitytracker.com/id?1018706http://www.ubuntu.com/usn/usn-696-1http://www.vupen.com/english/advisories/2007/2317https://exchange.xforce.ibmcloud.com/vulnerabilities/35036http://avahi.org/changeset/1482http://avahi.org/milestone/Avahi%200.6.20http://osvdb.org/37507http://secunia.com/advisories/25811http://secunia.com/advisories/26083http://secunia.com/advisories/26791http://secunia.com/advisories/33220http://secunia.com/advisories/33279http://www.debian.org/security/2008/dsa-1690http://www.mandriva.com/security/advisories?name=MDKSA-2007:185http://www.novell.com/linux/security/advisories/2007_14_sr.htmlhttp://www.securityfocus.com/archive/1/472443/100/0/threadedhttp://www.securityfocus.com/bid/24614http://www.securitytracker.com/id?1018706http://www.ubuntu.com/usn/usn-696-1http://www.vupen.com/english/advisories/2007/2317https://exchange.xforce.ibmcloud.com/vulnerabilities/35036
2007-06-22
Published