PT-2022-6752 · Avahi+9 · Avahi+9

Evverx

·

Published

2022-04-11

·

Updated

2025-01-15

·

CVE-2023-1981

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions avahi (affected versions not specified)
Description A flaw in the avahi library allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. This issue is related to an uncontrolled resource consumption, which can be exploited to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2023:6707
ALSA-2023:7190
AZL-26789
AZL-34554
BDU:2023-03858
CESA-2023_7190
CVE-2023-1981
DLA-3414-1
DLA-3990-1
MGASA-2023-0158
OESA-2023-1240
OPENSUSE-SU-2024:12854-1
RHSA-2023:6707
RHSA-2023:7190
RHSA-2023_6707
RHSA-2023_7190
RLSA-2023:7190
SUSE-SU-2023:1956-1
SUSE-SU-2023:1993-1
SUSE-SU-2023:1994-1
SUSE-SU-2023_1956-1
SUSE-SU-2023_1993-1
SUSE-SU-2023_1994-1
USN-6129-1
USN-6129-2

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Avahi