Lucene search

K
rosalinuxROSA LABROSA-SA-2024-2455
HistoryJul 23, 2024 - 11:22 a.m.

Advisory ROSA-SA-2024-2455

2024-07-2311:22:51
ROSA LAB
abf.rosalinux.ru
10
avahi 0.8
rosa-chrome
resolved
vulnerabilities
service discovery
exploitation
denial of service

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

software: avahi 0.8
WASP: ROSA-CHROME

package_evr_string: avahi-0.8-12.git35bb1b.2

CVE-ID: CVE-2021-26720
BDU-ID: 2022-05969
CVE-Crit: HIGH
CVE-DESC.: A vulnerability in the avahi-daemon-check-dns.sh component of the Avahi local area network service discovery system involves the execution of a script as the root user. Exploitation of the vulnerability allows an attacker to gain access to sensitive data, compromise its integrity, and cause a denial of service
CVE-STATUS: Resolved
CVE-REV: To close, run the command: sudo dnf update avahi

CVE-ID: CVE-2023-38469
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability has been discovered in Avahi where a reachable statement exists in avahi_dns_packet_append_record.
CVE-STATUS: Resolved
CVE-REV: To close, run the command: sudo dnf update avahi

CVE-ID: CVE-2023-38470
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability has been discovered in Avahi. There is a reachable statement in avahi_escape_label().
CVE-STATUS: It has been resolved
CVE-REV: To close, run the command: sudo dnf update avahi

CVE-ID: CVE-2023-38471
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability has been discovered in Avahi. A reachable statement exists in the dbus_set_host_name function.
CVE-STATUS: Fixed
CVE-REV: To close, execute the command: sudo dnf update avahi

CVE-ID: CVE-2023-38472
BDU-ID: 2023-08473
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability in the avahi_rdata_parse() function of the Avahi LAN service discovery system is related to a flaw in the exploitation of the function. Exploitation of the vulnerability allows an attacker to cause denial of service
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update avahi

CVE-ID: CVE-2023-38473
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC.: A vulnerability has been discovered in Avahi. A reachable statement exists in avahi_alternative_host_name().
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update avahi

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchavahi< 0.8UNKNOWN

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High