QID 242395
Date Published: 2023-11-15
QID 242395: Red Hat Update for avahi (RHSA-2023:6707)
Avahi is an implementation of the dns service discovery and multicast dns specifications for zero configuration networking.
It facilitates service discovery on a local network.
Avahi and avahi-aware applications allow you to plug your computer into a network and, with no configuration, view other people to chat with, view printers to print with, and find shared files on other computers...Security Fix(es):
- avahi: local dos by event-busy-loop from writing long lines to /run/avahi-daemon/socket (cve-2021-3468).
Avahi: reachable assertion in avahi_s_host_name_resolver_start when trying to resolve badly-formatted hostnames (cve-2021-3502).
Avahi: avahi-daemon can be crashed via dbus (cve-2023-1981).
- Red Hat enterprise linux for x86_64 9 x86_64.
Red hat enterprise linux for ibm z systems 9 s390x.
Red hat enterprise linux for power, little endian 9 ppc64le.
Red hat enterprise linux for arm 64 9 aarch64.
Red hat codeready linux builder for x86_64 9 x86_64.
Red hat codeready linux builder for power, little endian 9 ppc64le.
Red hat codeready linux builder for arm 64 9 aarch64.
Red hat codeready linux builder for ibm z systems 9 s390x.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Red Hat security advisory RHSA-2023:6707 for updates and patch information.
Vendor References
- RHSA-2023:6707 -
access.redhat.com/errata/RHSA-2023:6707
CVEs related to QID 242395
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| RHSA-2023:6707 | Red Hat Enterprise Linux |
|