CVE-2021-3502
published 2021-05-07CVE-2021-3502: A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.37%
29.6th percentile
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| avahi | avahi | — | — |
| avahi | avahi | >= 0 < 0.8-5+deb11u1 | 0.8-5+deb11u1 |
| avahi | avahi | >= 0 < 0.8-6 | 0.8-6 |
| avahi | avahi | >= 0 < 0.8-6 | 0.8-6 |
| avahi | avahi | >= 0 < 0.8-6 | 0.8-6 |
| avahi | avahi | >= 0 < 0.7-3.1ubuntu1.3 | 0.7-3.1ubuntu1.3 |
| avahi | avahi | >= 0 < 0.7-4ubuntu7.1 | 0.7-4ubuntu7.1 |
| debian | avahi | < avahi 0.8-6 (bookworm) | avahi 0.8-6 (bookworm) |
| msrc | azl3_avahi_0.8-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_avahi_0.8-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Avahi vulnerabilities
vendor_ubuntu·2021-07-07·CVSS 5.5
CVE-2021-3468 [MEDIUM] Avahi vulnerabilities
Title: Avahi vulnerabilities
Summary: Several security issues were fixed in Avahi.
Thomas Kremer discovered that Avahi incorrectly handled termination signals
on the Unix socket. A local attacker could possibly use this issue to cause
Avahi to hang, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-3468)
It was discovered that Avahi incorrectly handled certain hostnames. A local
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. This issue only affected Ubuntu 20.10 and Ubuntu
21.04. (CVE-2021-3502)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
avahi: local DoS against avahi-daemon via D-Bus interface
vendor_redhat·2021-07-07·CVSS 5.5
CVE-2021-36217 [MEDIUM] avahi: local DoS against avahi-daemon via D-Bus interface
avahi: local DoS against avahi-daemon via D-Bus interface
[REJECTED CVE] Avahi allows a local denial of service (NULL pointer dereference and daemon crash) against avahi-daemon via the D-Bus interface or a "ping .local" command.
Statement: This flaw was found to be a duplicate of CVE-2021-3502. Please see https://access.redhat.com/security/cve/CVE-2021-3502 for information about affected products and security errata.
Package: avahi (Red Hat Enterprise Linux 5) - Not affected
Package: avahi (Red Hat Enterprise Linux 6) - Not affected
Package: avahi (Red Hat Enterprise Linux 7) - Not affected
Package: avahi (Red Hat Enterprise Linux 8) - Not affected
Package: avahi (Red Hat Enterprise Linux 9) - Not affected
Microsoft
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions t
vendor_msrc·2021-05-11·CVSS 5.5
CVE-2021-3502 [MEDIUM] CWE-617 A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions t
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publish
Red Hat
avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames
vendor_redhat·2021-03-29·CVSS 5.5
CVE-2021-3502 [MEDIUM] CWE-617 avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames
avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
A flaw was found in avahi. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
Statement: This
Debian
CVE-2021-3502: avahi - A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_hos...
vendor_debian·2021·CVSS 5.5
CVE-2021-3502 [MEDIUM] CVE-2021-3502: avahi - A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_hos...
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
Scope: local
bookworm: resolved (fixed in 0.8-6)
bullseye: resolved (fixed in 0.8-5+deb11u1)
forky: resolved (fixed in 0.8-6)
sid: resolved (fixed in 0.8-6)
trixie: resolved (fixed in 0.8-6)
GHSA
GHSA-mw7q-3wxj-rqfx: A flaw was found in avahi 0
ghsa_unreviewed·2022-05-24
CVE-2021-3502 [MEDIUM] CWE-476 GHSA-mw7q-3wxj-rqfx: A flaw was found in avahi 0
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
OSV
avahi vulnerabilities
osv·2021-07-07·CVSS 5.5
CVE-2021-3468 [MEDIUM] avahi vulnerabilities
avahi vulnerabilities
Thomas Kremer discovered that Avahi incorrectly handled termination signals
on the Unix socket. A local attacker could possibly use this issue to cause
Avahi to hang, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2021-3468)
It was discovered that Avahi incorrectly handled certain hostnames. A local
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. This issue only affected Ubuntu 20.10 and Ubuntu
21.04. (CVE-2021-3502)
OSV
CVE-2021-3502: A flaw was found in avahi 0
osv·2021-05-07·CVSS 5.5
CVE-2021-3502 [MEDIUM] CVE-2021-3502: A flaw was found in avahi 0
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-07
Published