From a3c62c36118e00aae39ffbdba1aa4ad064a36d0f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adrian=20Schr=C3=B6ter?= Date: Thu, 5 Sep 2024 15:34:14 +0200 Subject: [PATCH] Adding patchinfo patchinfo.20240821152930070909.269002615871826 --- avahi | 2 +- .../_patchinfo | 27 +++++++++++++++++++ 2 files changed, 28 insertions(+), 1 deletion(-) create mode 100644 patchinfo.20240821152930070909.269002615871826/_patchinfo diff --git a/avahi b/avahi index afc3ad3..5f57cbe 160000 --- a/avahi +++ b/avahi @@ -1 +1 @@ -Subproject commit afc3ad3befb3224775ea136a69c1cdf75cf91613 +Subproject commit 5f57cbe813e4266eb349effa44dbd1129b48ee17 diff --git a/patchinfo.20240821152930070909.269002615871826/_patchinfo b/patchinfo.20240821152930070909.269002615871826/_patchinfo new file mode 100644 index 0000000..aca7b3b --- /dev/null +++ b/patchinfo.20240821152930070909.269002615871826/_patchinfo @@ -0,0 +1,27 @@ + + + VUL-0: CVE-2023-38471: avahi: Reachable assertion in dbus_set_host_name + VUL-0: CVE-2023-38469: avahi: CVEs assigned for reachable assertions in avahi + avahi-browse -a fails with "Invalid service type" + + + mgorse + moderate + security + Security update for avahi + This update for avahi fixes the following issues: + +Security issues fixed: + +- CVE-2023-38471: Extract host name using avahi_unescape_label (bsc#1216594). +- CVE-2023-38469: Reject overly long TXT resource records (bsc#1216598). + +Non-security issue fixed: + +- no longer supply bogus services to callbacks (bsc#1226586). + + avahi + avahi:glib2 + avahi:qt5 + +