ALT-PU-2025-1624-1
Package avahi updated to version 0.8-alt5 for branch sisyphus_riscv64.
Closed vulnerabilities
Published: 2024-11-22
Modified: 2025-05-14
Modified: 2025-05-14
CVE-2024-52616
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
References: