There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2024-52615:
(needs triaging)
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.
- CVE-2024-52616:
(needs triaging)
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
You can find information about how to handle these issues in the security team's documentation.