Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.
| Vendor | Product | Versions |
|---|---|---|
| avahi | avahi-daemon | < 0.9-rc4 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| open source | avahi | cert_advisory | 90% |
Updated affected versions to <=v0.9-rc3, marked exploit as available and actively exploited, and provided a detailed description of the vulnerability.
Updated affected versions to include 0.9-rc3, changed severity to HIGH, and specified patch available in version 0.9-rc4.
Initial creation