CVE-2006-5461
Summary
| CVE | CVE-2006-5461 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-11-14 22:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Avahi "netlink" Message Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Advisories - Mandriva Linux | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Avahi Lets Remote Users Manipulate the Service By Spoofing Netlink Messages - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Gentoo update for avahi - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Milestone Avahi 0.6.15 - Avahi - Trac | af854a3a-2127-422b-91ae-364da2661108 | avahi.org | |
| Ubuntu update for avahi - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Gentoo Linux Documentation -- Avahi: "netlink" message vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| http://0pointer.net/ | af854a3a-2127-422b-91ae-364da2661108 | tango.0pointer.de | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Mandriva update for avahi - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-380-1: Avahi vulnerability | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| Avahi Unauthorized Data Manipulation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.