Back

CRITICAL

avahi: Multicast DNS responds to unicast queries outside of local network

Published May 1, 2017

Description

avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as low severity because it allows a remote attacker to cause a denial of service or amplify traffic through crafted UDP packets, it could impact availability, it does not pose a significant risk to system integrity or confidentiality.

Red Hat mitigation

Ensure UDP port 5353 is blocked in the firewall. Moreover, configure correctly the rate limiting options based on your needs (see ratelimit-interval-usec and ratelimit-burst options in /etc/avahi/avahi-daemon.conf).

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 1, 2017
Updated Dec 3, 2025
Reserved Mar 7, 2017
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 31, 2015