CVE Vulnerabilities

CVE-2006-5461

Published: Nov 14, 2006 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.

Affected Software

Name Vendor Start Version End Version
Avahi Avahi * 0.6.14 (including)
Avahi Ubuntu dapper *
Avahi Ubuntu edgy *
Avahi Ubuntu upstream *

References