Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2023-1981
HistoryMay 26, 2023 - 6:15 p.m.

CVE-2023-1981

2023-05-2618:15:11
Alpine Linux Development Team
security.alpinelinux.org
14
vulnerability
avahi library
daemon crash
unprivileged user
dbus call
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

OSVersionArchitecturePackageVersionFilename
Alpineedge-mainnoarchavahi< 0.8-r14UNKNOWN
Alpine3.19-mainnoarchavahi< 0.8-r14UNKNOWN
Alpine3.20-mainnoarchavahi< 0.8-r14UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

AI Score

5.4

Confidence

High

EPSS

0

Percentile

5.1%