#VU17349 Input validation error in Avahi - CVE-2017-6519
Published: February 1, 2019
Avahi
avahi.org
Description
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to avahi-daemon inadvertently responds to IPv6 unicast queries with source addresses that are not on-link. A remote attacker can submit specially crafted port-5353 UDP packet to trigger traffic amplification and cause the service to crash.