CVE-2017-6519

Description

avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.

Risk Information

Base Score
9.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
Exploitation Probability
1.134

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2020:1176) avahi security update avahi-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-autoipd-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-howl-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-howl-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-howl-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-howl-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-libdns_sd-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-libdns_sd-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-libdns_sd-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-compat-libdns_sd-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-dnsconfd-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-glib-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-glib-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-glib-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-glib-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-gobject-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-gobject-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-gobject-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-gobject-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-libs-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-libs-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt3-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt3-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt3-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt3-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt4-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt4-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt4-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-qt4-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-tools-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-devel-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-devel-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-gtk3-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-gtk3-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176) avahi security update avahi-ui-tools-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-autoipd-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-compat-howl-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-compat-howl-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-compat-libdns_sd-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-compat-libdns_sd-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-dnsconfd-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-glib-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-glib-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-gobject-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-gobject-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-libs-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-qt3-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-qt3-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-qt4-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-qt4-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-tools-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-ui-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-ui-devel-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-ui-gtk3-0.6.31-20.el7.x86_64.rpmLinux
(CESA-2020:1176) avahi security update avahi-ui-tools-0.6.31-20.el7.x86_64.rpmLinux
(RHSA-2020:1176)Low: security update avahi-debuginfo-0.6.31-20.el7.i686.rpmLinux
(RHSA-2020:1176)Low: security update avahi-debuginfo-0.6.31-20.el7.x86_64.rpmLinux
Avahi update (ELSA-2020-1176) avahi-0.6.31-20.el7.i686.rpmLinux
Avahi update (ELSA-2020-1176) avahi-0.6.31-20.el7.x86_64.rpmLinux
Avahi-autoipd update (ELSA-2020-1176) avahi-autoipd-0.6.31-20.el7.x86_64.rpmLinux
Avahi-glib update (ELSA-2020-1176) avahi-glib-0.6.31-20.el7.i686.rpmLinux
Avahi-glib update (ELSA-2020-1176) avahi-glib-0.6.31-20.el7.x86_64.rpmLinux
Avahi-gobject update (ELSA-2020-1176) avahi-gobject-0.6.31-20.el7.i686.rpmLinux
Avahi-gobject update (ELSA-2020-1176) avahi-gobject-0.6.31-20.el7.x86_64.rpmLinux
Avahi-libs update (ELSA-2020-1176) avahi-libs-0.6.31-20.el7.i686.rpmLinux
Avahi-libs update (ELSA-2020-1176) avahi-libs-0.6.31-20.el7.x86_64.rpmLinux
Avahi-ui-gtk3 update (ELSA-2020-1176) avahi-ui-gtk3-0.6.31-20.el7.i686.rpmLinux
Avahi-ui-gtk3 update (ELSA-2020-1176) avahi-ui-gtk3-0.6.31-20.el7.x86_64.rpmLinux
Origin Validation Error Vulnerability (CVE-2017-6519)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234