CVE-2017-6519

Metadata

medium
6.4
avahi
CVE-2017-6519
cve.mitre.org, bugzilla.redhat.com, secfu.net, kb.cert.org
2017-04-30
2017-10-23 14:24
CVE-2017-6519 avahi
2017-07-20 21:33
2017-06-16 19:22
2017-06-15 17:13
2017-05-10 23:55
2017-05-01 19:03

Description

avahi-daemon in Avahi through 0.6.32 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Or, you can just let us figure it out for you! Appcanary continously monitor your installed packages, and tell you if any of them are vulnerable.

Sign up for monitoring

Affected package information

None

Unaffected

Release Package Reason
precise avahi ignored
vivid/stable-phone-overlay avahi ignored
vivid/ubuntu-core avahi DNE
yakkety avahi ignored

Needs Triage

Release Package Reason
upstream avahi needs-triage
precise/esm avahi needs-triage
trusty avahi needs-triage
xenial avahi needs-triage
zesty avahi needs-triage
artful avahi needs-triage
devel avahi needs-triage