REDHAT-BUG-2326418: Medium severity Avahi avahi-daemon vulnerability
This vulnerability exposes Avahi-daemon to potential DNS spoofing attacks by using a fixed source port for queries. However, the impact is limited because it only affects wide-area DNS and can be mitigated by forwarding queries to local DNS resolvers (e.g., systemd-resolved), which provide better randomization. The impact is primarily on systems actively using wide-area DNS, with .local mDNS being unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate DNS spoofing risk by forwarding wide-area DNS queries to local DNS resolvers (for example, systemd-resolved), which provide better randomization of query parameters.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2326418?
The severity of REDHAT-BUG-2326418 is considered moderate due to its limited impact on wide-area DNS.
How do I fix REDHAT-BUG-2326418?
To mitigate REDHAT-BUG-2326418, forward DNS queries to local DNS resolvers like systemd-resolved.
What systems are affected by REDHAT-BUG-2326418?
REDHAT-BUG-2326418 affects systems running the Avahi-daemon service.
Can REDHAT-BUG-2326418 lead to a successful attack?
Yes, REDHAT-BUG-2326418 can expose systems to DNS spoofing attacks if not mitigated properly.
What is the nature of the vulnerability in REDHAT-BUG-2326418?
The nature of the vulnerability in REDHAT-BUG-2326418 involves the use of a fixed source port for DNS queries.