CVE-2023-38470 is a medium-severity vulnerability affecting Avahi, specifically within the avahi_escape_label() function, and impacts various Avahi and Red Hat Enterprise Linux distributions. This local vulnerability, with low attack complexity, could lead to a denial of service (availability impact) if exploited. There is currently no public exploit code available, nor is it known to be actively exploited, with minimal community discussion and media coverage observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9CPE matchmatch criteria | cpe:2.3:a:avahi:avahi:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE match | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-38470
Dec 10, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024Reachable assertion in avahi_escape_label
Nov 14, 2023avahi: Reachable assertion in avahi_escape_label
Apr 26, 2023