Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9 MGASA-2024-0016 Critical: Avahi Assertion Threats

mageia
Calendar Grey January 25, 2024
Dist Mageia Esm H88
New avahi upgrades for Mageia tackle several security flaws, boosting protective features for its user base.
The updated packages fix security vulnerabilities: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record

Summary

The updated packages fix security vulnerabilities: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. (CVE-2023-38469) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. (CVE-2023-38470) A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. (CVE-2023-38471) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. (CVE-2023-38472) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. (CVE-2023-38473)

References

- https://bugs.mageia.org/show_bug.cgi?id=32363

- https://www.cve.org/CVERecord?id=CVE-2023-38469

- https://www.cve.org/CVERecord?id=CVE-2023-38470

- https://www.cve.org/CVERecord?id=CVE-2023-38471

- https://www.cve.org/CVERecord?id=CVE-2023-38472

- https://www.cve.org/CVERecord?id=CVE-2023-38473

Resolution

SRPMS

- 9/core/avahi-0.8-10.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 25 Jan 2024
URL: https://advisories.mageia.org/MGASA-2024-0016.html
Type: security
CVE: CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here