ALT-PU-2019-2684-1
Closed vulnerabilities
Published: 2018-12-20
BDU:2019-00693
Уязвимость демона avahi-daemon системы обнаружения сервисов в локальной сети Avahi, позволяющая нарушителю раскрыть защищаемую информацию или вызвать отказ в обслуживании
Severity: CRITICAL (9.1)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
References:
Published: 2017-05-01
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-6519
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.
Severity: CRITICAL (9.1)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
References:
- https://bugzilla.redhat.com/show_bug.cgi?id=1426712
- https://bugzilla.redhat.com/show_bug.cgi?id=1426712
- https://github.com/lathiat/avahi/issues/203
- https://github.com/lathiat/avahi/issues/203
- https://github.com/lathiat/avahi/issues/203#issuecomment-449536790
- https://github.com/lathiat/avahi/issues/203#issuecomment-449536790
- [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image
- [bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image
- USN-3876-1
- USN-3876-1
- USN-3876-2
- USN-3876-2
- https://www.secfu.net/advisories
- https://www.secfu.net/advisories
No data currently available.