VDB
CISA-2017-6519
CISA-2017-6519
PUBLISHED
CVSS 9.1 CRITICAL
Reported by mitre · Published May 1, 2017
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | *, n/a |
Timeline
- May 1, 2017 CVE Published
- Dec 3, 2025 CVE Updated
References
- x_refsource_MISC
- USN-3876-1 vendor-advisoryx_refsource_UBUNTU
- x_refsource_MISC
- x_refsource_MISC
- USN-3876-2 vendor-advisoryx_refsource_UBUNTU
- x_refsource_MISC
- [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image mailing-listx_refsource_MLIST