Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 11: DLA-3990-1 moderate: multiple issues in avahi software

debian lts
Calendar Grey December 9, 2024
Dist Debian Esm H88
Debian LTS Advisory DLA-3991-1 regarding openssl highlights urgent vulnerabilities. Update immediately to ensure safety.
Multiple vulnerabilities have been fixed in the service discovery system Avahi

Summary

CVE-2023-1981

avahi-daemon can be crashed via DBus

CVE-2023-38469

Reachable assertion in avahi_dns_packet_append_record

CVE-2023-38470

Reachable assertion in avahi_escape_label

CVE-2023-38471

Reachable assertion in dbus_set_host_name

CVE-2023-38472

Reachable assertion in avahi_rdata_parse

CVE-2023-38473

Reachable assertion in avahi_alternative_host_name

For Debian 11 bullseye, these problems have been fixed in version
0.8-5+deb11u3.

We recommend that you upgrade your avahi packages.

For the detailed security status of avahi please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/avahi

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
important
Lowest
Low
Medium
High
Critical

Package: avahi
Version: 0.8-5+deb11u3
CVE ID: CVE-2023-1981 CVE-2023-38469 CVE-2023-38470 CVE-2023-38471
Debian Bug: 1034594 1054876 1054877 1054878 1054879 1054880

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here