NULL pointer dereference in Avahi - CVE-2021-36217

 

NULL pointer dereference in Avahi - CVE-2021-36217

Published: July 12, 2021 / Updated: November 20, 2023


Vulnerability identifier: #VU54661
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-36217
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the D-Bus interface. A local attacker can trigger denial of service conditions via the D-Bus interface or a "ping .local" command.


Affected software

Avahi
openEuler
Fedora
avahi-compat-libdns_sd-devel
avahi-help
avahi-debuginfo
avahi-compat-howl-devel
avahi-glib
avahi-gobject
avahi-ui-gtk3
avahi-compat-howl
avahi-ui-devel
avahi-devel
avahi-libs
avahi-tools
avahi-compat-libdns_sd
avahi-ui
avahi-debugsource
avahi-dnsconfd
avahi

How to mitigate CVE-2021-36217

Install update from vendor's website.

avahi-compat-libdns_sd-devel - update to 0.8-5
avahi-help - update to 0.8-5
avahi-debuginfo - update to 0.8-5
avahi-compat-howl-devel - update to 0.8-5
avahi-glib - update to 0.8-5
avahi-gobject - update to 0.8-5
avahi-ui-gtk3 - update to 0.8-5
avahi-compat-howl - update to 0.8-5
avahi-ui-devel - update to 0.8-5
avahi-devel - update to 0.8-5
avahi-libs - update to 0.8-5
avahi-tools - update to 0.8-5
avahi-compat-libdns_sd - update to 0.8-5
avahi-ui - update to 0.8-5
avahi-debugsource - update to 0.8-5
avahi-dnsconfd - update to 0.8-5
avahi - update to 0.8-5
avahi - addressed in versions 0.8-14.fc33, 0.8-14.fc34

External References

Related Security Bulletins