Msrc Azl3 Avahi 0.8-5 On Azure Linux 3.0 vulnerabilities
11 known vulnerabilities affecting msrc/azl3_avahi_0.8-5_on_azure_linux_3.0.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2025-59529MEDIUMCVSS 5.52025-12-09
CVE-2025-59529 [MEDIUM] CWE-400 simple protocol server ignores accepts unlimited connections and logs failures without limit
simple protocol server ignores accepts unlimited connections and logs failures without limit
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
msrc
CVE-2024-52616MEDIUMCVSS 5.32024-11-12
CVE-2024-52616 [MEDIUM] CWE-334 Avahi: avahi wide-area dns predictable transaction ids
Avahi: avahi wide-area dns predictable transaction ids
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which t
msrc
CVE-2023-38473MEDIUMCVSS 6.22023-11-14
CVE-2023-38473 [MEDIUM] CWE-617 Reachable assertion in avahi_alternative_host_name
Reachable assertion in avahi_alternative_host_name
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distr
msrc
CVE-2023-38469MEDIUMCVSS 5.52023-11-14
CVE-2023-38469 [MEDIUM] CWE-617 Reachable assertion in avahi_dns_packet_append_record
Reachable assertion in avahi_dns_packet_append_record
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the
msrc
CVE-2023-38472MEDIUMCVSS 6.22023-11-14
CVE-2023-38472 [MEDIUM] CWE-617 Reachable assertion in avahi_rdata_parse
Reachable assertion in avahi_rdata_parse
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Micro
msrc
CVE-2023-38470MEDIUMCVSS 6.22023-11-14
CVE-2023-38470 [MEDIUM] CWE-617 Reachable assertion in avahi_escape_label
Reachable assertion in avahi_escape_label
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Mic
msrc
CVE-2023-38471MEDIUMCVSS 6.22023-11-14
CVE-2023-38471 [MEDIUM] CWE-617 Reachable assertion in dbus_set_host_name
Reachable assertion in dbus_set_host_name
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Mic
msrc
CVE-2023-1981MEDIUMCVSS 5.52023-05-09
CVE-2023-1981 [MEDIUM] CWE-400 A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call causing the avahi daemon to crash.
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call causing the avahi daemon to crash.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our custome
msrc
CVE-2021-3468MEDIUMCVSS 5.52021-06-08
CVE-2021-3468 [MEDIUM] CWE-835 A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function all
A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection on the avahi Unix socket is not correctly handled in the client_work function allowing a local attacker to trigger an infinite loop. The highest thre
msrc
CVE-2021-3502MEDIUMCVSS 5.52021-05-11
CVE-2021-3502 [MEDIUM] CWE-617 A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions t
A flaw was found in avahi 0.8-5. A reachable assertion is present in avahi_s_host_name_resolver_start function allowing a local attacker to crash the avahi service by requesting hostname resolutions through the avahi socket or dbus methods for invalid hostnames. The h
msrc
CVE-2021-26720HIGHCVSS 7.82021-02-09
CVE-2021-26720 [HIGH] CWE-59 avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon and allows a local attacker to cause a denial of service or create arbitra
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon and allows a local attacker to cause a denial of service or create arbitrary empty files via a symlink attack on files under /run/avahi-daemon.
msrc