CVE-2021-3502 is a medium-severity vulnerability affecting Avahi 0.8-5, where a local attacker can crash the Avahi service by requesting hostname resolutions for invalid hostnames. This flaw, a reachable assertion in the avahi_s_host_name_resolver_start function, primarily impacts service availability. The vulnerability has a CVSS score of 5.5, indicating a local attack vector with low complexity and high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting a low current threat profile.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8-5CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:0.8-5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-3502
Jun 11, 2024A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.
May 11, 2021avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames
Mar 29, 2021