Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-52615

Published: November 19, 2024Last modified: July 18, 2025

Description

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

Severity score breakdown

ParameterValue
Base score5.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactLOW
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Notes

There was a PR that look like a fix for this CVE that got merged a couple days ago, but other distros is slow to react to it as of Jun 24 2025: https://github.com/avahi/avahi/pull/662

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSavahiFixed (0.8-r8)
StreamavahiFixed (0.8-r21)

References

ON THIS PAGE