CVE-2023-38472

medium
Published 2024-04-30 Β· Modified 2023-12-14
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2023:7836: avahi security update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description avahi: Reachable assertion in avahi_rdata_parse CVSS v3: 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 8avahi-0:0.7-21.el8_9.1RHSA-2023:78362023-12-14T00:00:00Z Red Hat Enterprise Linux 8avahi-0:0.7-21.el8_9.1RHSA-2023:78362023-12-14T00:00:00Z Red Hat Enterprise Linux 8.6 Extended Update…

Description

avahi: Reachable assertion in avahi_rdata_parse

CVSS v3: 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8avahi-0:0.7-21.el8_9.1RHSA-2023:78362023-12-14T00:00:00Z
Red Hat Enterprise Linux 8avahi-0:0.7-21.el8_9.1RHSA-2023:78362023-12-14T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportavahi-0:0.7-20.el8_6.3RHSA-2024:04182024-01-25T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportavahi-0:0.7-20.el8_8.4RHSA-2024:05762024-01-30T00:00:00Z
Red Hat Enterprise Linux 9avahi-0:0.8-20.el9RHSA-2024:24332024-04-30T00:00:00Z
Red Hat Enterprise Linux 9avahi-0:0.8-20.el9RHSA-2024:24332024-04-30T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6avahiOut of support scope
Red Hat Enterprise Linux 7avahiOut of support scope

Apply commands

bash fix
Apply RHSA-2023:7836 for Red Hat Enterprise Linux 8
yum update -y avahi
# or:
dnf upgrade -y avahi

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed avahi-0.7-21.el8_9.1.i686.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.8-14
sid Fixed 0.8-14
forky Fixed 0.8-14
bullseye Fixed 0.8-5+deb11u3
bookworm Fixed 0.8-10+deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.