PT-2021-7394 · Debian+2 · Avahi+2

Matthias Gerstner

·

Published

2021-02-15

·

Updated

2024-07-23

·

CVE-2021-26720

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4
Description The issue is related to the execution of avahi-daemon-check-dns.sh as root via /etc/network/if-up.d/avahi-daemon, allowing a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. This affects the packaging for Debian GNU/Linux, used indirectly by SUSE, but not the upstream Avahi product. The vulnerability can also lead to unauthorized access to confidential data and disruption of their integrity.
Recommendations For avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4, consider disabling the execution of the script as root via /etc/network/if-up.d/avahi-daemon as a temporary workaround to minimize the risk of exploitation. Restrict access to files under /run/avahi-daemon to prevent a symlink attack. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Link Following

Weakness Enumeration

Related Identifiers

AZL-34547
AZL-6323
BDU:2022-05969
CVE-2021-26720
DLA-3047-1
OPENSUSE-SU-2021:0370-1
OPENSUSE-SU-2021:1845-1
OPENSUSE-SU-2021_0370-1
OPENSUSE-SU-2021_1845-1
OPENSUSE-SU-2024:10643-1
ROSA-SA-2024-2455
SUSE-SU-2021:0551-1
SUSE-SU-2021:0563-1
SUSE-SU-2021:1845-1
SUSE-SU-2021_0551-1
SUSE-SU-2021_0563-1
SUSE-SU-2021_1845-1

Affected Products

Astra Linux
Suse
Avahi