CVE-2017-6519
Summary
| CVE | CVE-2017-6519 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-01 01:59:00 UTC |
| Updated | 2023-11-07 02:49:00 UTC |
| Description | avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Missing link-local checks in Avahi makes DDoS with mDNS traffic reflection possible · Issue #203 · lathiat/avahi · GitHub |
MISC |
github.com |
Exploit, Third Party Advisory |
| 1426712 – (CVE-2017-6519) CVE-2017-6519 avahi: Multicast DNS responds to unicast queries outside of local network |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| Missing link-local checks in Avahi makes DDoS with mDNS traffic reflection possible · Issue #203 · lathiat/avahi · GitHub |
MISC |
github.com |
Third Party Advisory |
| USN-3876-1: Avahi vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| Avahi IPv6 Off-link Unicast mDNS Interaction - A few tools and articiles for IT security topics |
MISC |
www.secfu.net |
Third Party Advisory |
| USN-3876-2: Avahi vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377318 Alibaba Cloud Linux Security Update for avahi (ALINUX2-SA-2020:0045)
- 500041 Alpine Linux Security Update for avahi
- 503057 Alpine Linux Security Update for avahi
- 503325 Alpine Linux Security Update for avahi
- 503399 Alpine Linux Security Update for avahi
- 503471 Alpine Linux Security Update for avahi
- 503488 Alpine Linux Security Update for avahi
- 503515 Alpine Linux Security Update for avahi
- 503563 Alpine Linux Security Update for avahi
- 503600 Alpine Linux Security Update for avahi
- 503635 Alpine Linux Security Update for avahi
- 503654 Alpine Linux Security Update for avahi
- 505849 Alpine Linux Security Update for avahi
- 901947 Common Base Linux Mariner (CBL-Mariner) Security Update for avahi (6322-1)