In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for Debian:unstable
avahi
.
Note: Versions mentioned in the description apply only to the upstream avahi
package and not the avahi
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.