Back to search
CVE-2021-26720
Published: Feb 17, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: this only affects the packaging for Debian GNU/Linux (used indirectly by SUSE), not the upstream Avahi product.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://packages.debian.org/buster/avahi-daemon
x_refsource_MISC
https://packages.debian.org/sid/avahi-daemon
x_refsource_MISC
https://packages.debian.org/bullseye/avahi-daemon
x_refsource_MISC
https://security-tracker.debian.org/tracker/CVE-2021-26720
x_refsource_MISC
https://bugs.launchpad.net/ubuntu/+source/avahi/+bug/1870824
x_refsource_MISC
https://www.openwall.com/lists/oss-security/2021/02/15/2
x_refsource_MISC
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=982796
x_refsource_MISC
https://bugzilla.suse.com/show_bug.cgi?id=1180827
x_refsource_MISC
[debian-lts-announce] 20220607 [SECURITY] [DLA 3047-1] avahi security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now