rpm package
suse/avahi-glib2&distro=SUSE Linux Enterprise Software Development Kit 12 SP5
pkg:rpm/suse/avahi-glib2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-38473 | — | < 0.6.32-32.21.1 | 0.6.32-32.21.1 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function. | ||
| CVE-2023-38472 | — | < 0.6.32-32.27.1 | 0.6.32-32.27.1 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. | ||
| CVE-2023-38471 | — | < 0.6.32-32.24.1 | 0.6.32-32.24.1 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function. | ||
| CVE-2023-38470 | — | < 0.6.32-32.27.1 | 0.6.32-32.27.1 | Nov 2, 2023 | A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. | ||
| CVE-2023-38469 | — | < 0.6.32-32.24.1 | 0.6.32-32.24.1 | Nov 2, 2023 | A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. | ||
| CVE-2023-1981 | — | < 0.6.32-32.18.1 | 0.6.32-32.18.1 | May 26, 2023 | A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. | ||
| CVE-2021-3468 | — | < 0.6.32-32.15.1 | 0.6.32-32.15.1 | Jun 2, 2021 | A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from thi | ||
| CVE-2021-26720 | — | < 0.6.32-32.12.3 | 0.6.32-32.12.3 | Feb 17, 2021 | avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: thi |
- CVE-2023-38473Nov 2, 2023affected < 0.6.32-32.21.1fixed 0.6.32-32.21.1
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
- CVE-2023-38472Nov 2, 2023affected < 0.6.32-32.27.1fixed 0.6.32-32.27.1
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
- CVE-2023-38471Nov 2, 2023affected < 0.6.32-32.24.1fixed 0.6.32-32.24.1
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
- CVE-2023-38470Nov 2, 2023affected < 0.6.32-32.27.1fixed 0.6.32-32.27.1
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
- CVE-2023-38469Nov 2, 2023affected < 0.6.32-32.24.1fixed 0.6.32-32.24.1
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
- CVE-2023-1981May 26, 2023affected < 0.6.32-32.18.1fixed 0.6.32-32.18.1
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
- CVE-2021-3468Jun 2, 2021affected < 0.6.32-32.15.1fixed 0.6.32-32.15.1
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function, allowing a local attacker to trigger an infinite loop. The highest threat from thi
- CVE-2021-26720Feb 17, 2021affected < 0.6.32-32.12.3fixed 0.6.32-32.12.3
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon. NOTE: thi