There are 7 open security issues in bookworm.
7 issues left for the package maintainer to handle:
- CVE-2023-38469:
(needs triaging)
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
- CVE-2023-38470:
(needs triaging)
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
- CVE-2023-38471:
(needs triaging)
A vulnerability was found in Avahi. A reachable assertion exists in the dbus_set_host_name function.
- CVE-2023-38472:
(needs triaging)
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
- CVE-2023-38473:
(needs triaging)
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.
- CVE-2024-52615:
(needs triaging)
A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.
- CVE-2024-52616:
(needs triaging)
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
You can find information about how to handle these issues in the security team's documentation.