ALT-PU-2025-1638-1
Package avahi updated to version 0.8-alt5 for branch sisyphus_loongarch64.
Closed vulnerabilities
Published: 2024-11-22
CVE-2024-52616
A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable behavior facilitates DNS spoofing attacks, allowing attackers to guess transaction IDs.
Severity: MEDIUM (5.3)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
References: