CVE-2017-6519 describes a critical vulnerability in avahi-daemon, affecting Avahi through versions 0.6.32 and 0.7, as well as Canonical Ubuntu Linux. This flaw allows remote attackers to trigger a denial of service via traffic amplification and potentially leak sensitive information by exploiting the daemon's inadvertent response to off-link IPv6 unicast queries on UDP port 5353. With a CVSS score of 9.1 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and high impacts on confidentiality and availability. Despite its severity, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.6.32CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:* | ||
0.7CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:0.7:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-6519
Dec 14, 2021avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.
May 9, 2017avahi: Multicast DNS responds to unicast queries outside of local network
Mar 31, 2015