USN-6129-1: Avahi vulnerability
Published Jun 1, 2023
·Updated
It was discovered that Avahi incorrectly handled certain DBus messages. A local attacker could possibly use this issue to cause Avahi to crash, resulting in a denial of service.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/avahi-daemon<0.8-6ubuntu1.23.04.1
0.8-6ubuntu1.23.04.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/avahi-daemon<0.8-6ubuntu1.22.10.1
0.8-6ubuntu1.22.10.1
Ubuntu Ubuntu=22.10
All of the following
ubuntu/avahi-daemon<0.8-5ubuntu5.1
0.8-5ubuntu5.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/avahi-daemon<0.7-4ubuntu7.2
0.7-4ubuntu7.2
Ubuntu Ubuntu=20.04
Event History
Jun 1, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Avahi vulnerability?
The vulnerability ID for this Avahi vulnerability is USN-6129-1.
2
What is the severity of the Avahi vulnerability?
The severity of the Avahi vulnerability is not specified in the information provided.
3
How does this vulnerability impact Avahi?
This vulnerability could be exploited by a local attacker to cause Avahi to crash, resulting in a denial of service.
4
Which versions of Avahi are affected by this vulnerability?
The versions of Avahi affected by this vulnerability are 0.8-6ubuntu1.23.04.1, 0.8-6ubuntu1.22.10.1, 0.8-5ubuntu5.1, and 0.7-4ubuntu7.2.
5
How can I fix the Avahi vulnerability?
To fix the Avahi vulnerability, update Avahi to version 0.8-6ubuntu1.23.04.1 or later, 0.8-6ubuntu1.22.10.1 or later, 0.8-5ubuntu5.1 or later, or 0.7-4ubuntu7.2 or later.