Wind River Support Network

HomeDefectsLIN1021-277
Fixed

LIN1021-277 : Security Advisory - avahi - CVE-2021-3502

Created: May 24, 2021    Updated: Dec 17, 2021
Resolved Date: Sep 26, 2021
Found In Version: 10.21.20.1
Fix Version: 10.21.20.6
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames

The vulnerability was introduced in upstream commit https://github.com/lathiat/avahi/commit/80c98fa16782e921f5b5d5c880f1d80f5c43bd49, which was shipped with upstream version 0.8.


CREATE(Triage):(User=admin) CVE-2021-3502 (https://nvd.nist.gov/vuln/detail/CVE-2021-3502)

CVEs


Live chat
Online