VUL-0: CVE-2023-38471: avahi: Reachable assertion in dbus_set_host_name
VUL-0: CVE-2023-38469: avahi: CVEs assigned for reachable assertions in avahi
avahi-browse -a fails with "Invalid service type"
mgorse
moderate
security
Security update for avahi
This update for avahi fixes the following issues:
Security issues fixed:
- CVE-2023-38471: Extract host name using avahi_unescape_label (bsc#1216594).
- CVE-2023-38469: Reject overly long TXT resource records (bsc#1216598).
Non-security issue fixed:
- no longer supply bogus services to callbacks (bsc#1226586).
avahi
avahi:glib2
avahi:qt5