Vulnerabilities > CVE-2021-3502 - Reachable Assertion vulnerability in Avahi 0.85

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
avahi
CWE-617

Summary

A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The highest threat from this vulnerability is to the service availability.

Vulnerable Configurations

Part Description Count
Application
Avahi
1

Common Weakness Enumeration (CWE)