CVE-2023-38472: Reachable assertion in avahi_rdata_parse
Published Apr 28, 2023
·Updated
A reachable assertion was found in avahirdataparse.
References:
https://github.com/lathiat/avahi/issues/452
Other sources
A vulnerability was found in Avahi. A reachable assertion exists in the avahirdataparse() function.
— MITRE
Affected Software
3 affected components
Avahi Avahi<0.9
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Event History
Apr 28, 2023
Data Sourced
via Red Hat·07:57 PM
DescriptionSeverityAffected Software
Nov 2, 2023
CVE Published
via MITRE·02:59 PM
Data Sourced
via MITRE·02:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-38472?
CVE-2023-38472 is a vulnerability found in Avahi where a reachable assertion exists in the avahi_rdata_parse() function.
2
How does CVE-2023-38472 impact Avahi?
CVE-2023-38472 can be exploited to trigger a reachable assertion in Avahi.
3
What is the severity of CVE-2023-38472?
CVE-2023-38472 has a severity rating of 6.2 (Medium).
4
Which software is affected by CVE-2023-38472?
Avahi versions up to and excluding 0.9, Redhat Enterprise Linux 8.0, and Redhat Enterprise Linux 9.0 are affected by CVE-2023-38472.
5
Is there a fix available for CVE-2023-38472?
Yes, a fix is available for CVE-2023-38472. Please refer to the references for more information.