VYPR

rpm package

almalinux/avahi-gobject

pkg:rpm/almalinux/avahi-gobject

Vulnerabilities (8)

  • CVE-2024-52616MedNov 21, 2024
    affected < 0.8-22.el9_6fixed 0.8-22.el9_6

    A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.

  • CVE-2023-38473Nov 2, 2023
    affected < 0.7-21.el8_9.1fixed 0.7-21.el8_9.1

    A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.

  • CVE-2023-38472Nov 2, 2023
    affected < 0.7-21.el8_9.1fixed 0.7-21.el8_9.1

    A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.

  • CVE-2023-38471Nov 2, 2023
    affected < 0.7-21.el8_9.1fixed 0.7-21.el8_9.1

    A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.

  • CVE-2023-38470Nov 2, 2023
    affected < 0.7-21.el8_9.1fixed 0.7-21.el8_9.1

    A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.

  • CVE-2023-38469Nov 2, 2023
    affected < 0.7-21.el8_9.1fixed 0.7-21.el8_9.1

    A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.

  • CVE-2023-1981May 26, 2023
    affected < 0.7-21.el8fixed 0.7-21.el8

    A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

  • CVE-2021-3468Jun 2, 2021
    affected < 0.7-21.el8_9.1fixed 0.7-21.el8_9.1

    A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from thi