CVE-2023-1981: Medium severity avahi utilities vulnerability
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Other sources
It was discovered that the avahi deamon can be locally crashed by a dbus call made by an unprivileged user, causing a denial of service.
References:
https://github.com/lathiat/avahi/issues/375
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-1981?
CVE-2023-1981 is a vulnerability found in the avahi library, allowing an unprivileged user to make a dbus call and crash the avahi daemon.
How severe is CVE-2023-1981?
CVE-2023-1981 has a severity score of 6.2, which is considered medium.
Which software is affected by CVE-2023-1981?
The avahi library version 0.7-20 and various versions of Fedora and Redhat Enterprise Linux are affected.
How can I fix CVE-2023-1981 in Ubuntu?
To fix CVE-2023-1981 in Ubuntu, update the avahi package to version 0.8-5ubuntu5.1 or later.
Are there any references for CVE-2023-1981?
Yes, you can find references for CVE-2023-1981 at the following links: [CVE](https://www.cve.org/CVERecord?id=CVE-2023-1981), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-1981), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2185911), [Red Hat](https://access.redhat.com/security/cve/CVE-2023-1981).