CVE-2023-1981Uncontrolled Resource Consumption in Avahi

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26
Latest updateJul 25

Description

A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debianavahi/avahi< 0.8-5+deb11u3+3
CVEListV5avahi/avahiavahi-0.7-20
NVDavahi/avahi0.7-20

Also affects: Fedora 37, Enterprise Linux 6.0, 7.0, 8.0, 9.0

🔴Vulnerability Details

3
OSV
CVE-2023-1981: A vulnerability was found in the avahi library2023-05-26
CVEList
CVE-2023-1981: A vulnerability was found in the avahi library2023-05-26
GHSA
GHSA-55h6-xcvg-4r99: A vulnerability was found in the avahi library2023-05-26

📋Vendor Advisories

5
Ubuntu
Avahi vulnerability2023-07-25
Ubuntu
Avahi vulnerability2023-06-01
Microsoft
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call causing the avahi daemon to crash.2023-05-09
Debian
CVE-2023-1981: avahi - A vulnerability was found in the avahi library. This flaw allows an unprivileged...2023
Red Hat
avahi: avahi-daemon can be crashed via DBus2022-04-26
CVE-2023-1981 — Uncontrolled Resource Consumption | cvebase