New Debian avahi 0.7-4+deb10u4 fixes: This update addresses the following issues: 0.7-4+deb10u4 (Sun, 08 Dec 2024 18:23:25 +0200) * Non-maintainer upload by the ELTS Team. * CVE-2023-38469: Reachable assertion in avahi_dns_packet_append_record * CVE-2023-38470: Reachable assertion in avahi_escape_label * CVE-2023-38471: Reachable assertion in dbus_set_host_name * CVE-2023-38472: Reachable assertion in avahi_rdata_parse * CVE-2023-38473: Reachable assertion in avahi_alternative_host_name * Fixed a GetAlternativeServiceName regression introduced by the CVE-2023-1981 fix in 0.7-4+deb10u2.
--- mirror/ftp/pool/main/a/avahi/avahi_0.7-4+deb10u3.dsc +++ apt/ucs_5.0-0-errata5.0-9/source/avahi_0.7-4+deb10u4.dsc @@ -1,3 +1,14 @@ +0.7-4+deb10u4 [Sun, 08 Dec 2024 18:23:25 +0200] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload by the ELTS Team. + * CVE-2023-38469: Reachable assertion in avahi_dns_packet_append_record + * CVE-2023-38470: Reachable assertion in avahi_escape_label + * CVE-2023-38471: Reachable assertion in dbus_set_host_name + * CVE-2023-38472: Reachable assertion in avahi_rdata_parse + * CVE-2023-38473: Reachable assertion in avahi_alternative_host_name + * Fixed a GetAlternativeServiceName regression introduced + by the CVE-2023-1981 fix in 0.7-4+deb10u2. + 0.7-4+deb10u3 [Wed, 21 Jun 2023 19:29:18 +0000] Bastien Roucariès <rouca@debian.org>: * Non-maintainer upload by the Debian LTS security team. <http://piuparts.knut.univention.de/5.0-9/#2734323323169621535>
OK: bug OK: yaml OK: announce_errata OK: patch ~OK: piuparts Freexian provide new *-dbgsym [5.0-9] 6dca69d4d0 Bug #57809: avahi 0.7-4+deb10u4 doc/errata/staging/avahi.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) [5.0-9] 7494650266 Bug #57809: avahi 0.7-4+deb10u4 doc/errata/staging/avahi.yaml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x1189>