CVE-2021-3468
Last modified
CVE-2021-3468 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from this vulnerability is to the availability of the avahi service, which becomes unresponsive after this flaw is triggered.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avahi | Avahi | >= 0.6, <= 0.8 |
| Debian | Debian Linux | 9.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1939614Issue Tracking
- https://lists.debian.org/debian-lts-announce/2022/06/msg00009.htmlMailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1939614Issue Tracking
- https://lists.debian.org/debian-lts-announce/2022/06/msg00009.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3468?
How severe is CVE-2021-3468?
How do I fix CVE-2021-3468?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-34667The Calendar_plugin WordPress plugin is vulnerable to Reflec…6.1
- CVE-2021-34668The WordPress Real Media Library WordPress plugin is vulnera…5.4
- CVE-2021-3467A NULL pointer dereference flaw was found in the way Jasper …5.5
- CVE-2021-34675Basix NEX-Forms through 7.8.7 allows authentication bypass f…7.5
- CVE-2021-34676Basix NEX-Forms through 7.8.7 allows authentication bypass f…7.5
- CVE-2021-34679Thycotic Password Reset Server before 5.3.0 allows credentia…7.5
- CVE-2021-34682Receita Federal IRPF 2021 1.7 allows a man-in-the-middle att…3.7
- CVE-2021-34683An issue was discovered in EXCELLENT INFOTEK CORPORATION (EI…5.3
- CVE-2021-34684Hitachi Vantara Pentaho Business Analytics through 9.1 allow…9.8
- CVE-2021-34685UploadService in Hitachi Vantara Pentaho Business Analytics …7.2
- CVE-2021-34686Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-34687iDrive RemotePC before 7.6.48 on Windows allows information …5.3
Are you affected by CVE-2021-3468?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
