Lucene search

K
mageiaGentoo FoundationMGASA-2024-0016
HistoryJan 25, 2024 - 2:21 p.m.

Updated avahi packages fix security vulnerabilities

2024-01-2514:21:08
Gentoo Foundation
advisories.mageia.org
18
avahi
packages
security
vulnerabilities
assertion error
reachable
cve-2023-38469
cve-2023-38470
cve-2023-38471
cve-2023-38472
cve-2023-38473
dbus_set_host_name
avahi_dns_packet_append_record
avahi_escape_label
avahi_rdata_parse
avahi_alternative_host_name
unix

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

The updated packages fix security vulnerabilities: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. (CVE-2023-38469) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. (CVE-2023-38470) A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. (CVE-2023-38471) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. (CVE-2023-38472) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. (CVE-2023-38473)

OSVersionArchitecturePackageVersionFilename
Mageia9noarchavahi< 0.8-10.1avahi-0.8-10.1.mga9

6.2 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%