This repository was archived by the owner on Jan 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 89
Expand file tree
/
Copy pathavahi.advisories.yaml
More file actions
105 lines (96 loc) · 2.5 KB
/
Copy pathavahi.advisories.yaml
File metadata and controls
105 lines (96 loc) · 2.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
schema-version: 2.0.2
package:
name: avahi
advisories:
- id: CGA-9v95-w22g-6294
aliases:
- CVE-2023-38471
- GHSA-h3x3-j454-4phv
events:
- timestamp: 2024-02-09T01:58:28Z
type: fixed
data:
fixed-version: 0.9_rc1-r0
- id: CGA-h7pp-jxxp-p9gx
aliases:
- CVE-2023-38472
- GHSA-4g3h-v9fp-pgm4
events:
- timestamp: 2024-02-09T01:58:44Z
type: fixed
data:
fixed-version: 0.9_rc1-r0
- id: CGA-h88c-2gpj-jff4
aliases:
- CVE-2021-3468
- GHSA-43rm-fv4g-cmj8
events:
- timestamp: 2023-06-20T14:47:42Z
type: detection
data:
type: manual
- timestamp: 2023-06-20T16:14:33Z
type: fixed
data:
fixed-version: 0.8-r1
- id: CGA-hrvw-px4c-vvp2
aliases:
- CVE-2025-59529
events:
- timestamp: 2025-12-20T11:04:54Z
type: detection
data:
type: scan/v1
data:
subpackageName: avahi
componentID: 2623ef2b32c1da8d
componentName: avahi
componentVersion: 0.9_rc1-r44
componentType: apk
componentLocation: /.PKGINFO
scanner: grype
- timestamp: 2025-12-30T16:59:35Z
type: pending-upstream-fix
data:
note: It's not currently possible to remediate this CVE. However, upstream are actively developing a fix (see https://github.com/avahi/avahi/pull/808)
- id: CGA-p7w9-rr5h-r6q3
aliases:
- CVE-2023-38469
- GHSA-cg96-q9gq-2pr7
events:
- timestamp: 2024-02-09T01:57:54Z
type: fixed
data:
fixed-version: 0.9_rc1-r0
- id: CGA-px63-w5ph-wr78
aliases:
- CVE-2023-38470
- GHSA-mg8v-g9mc-p4f8
events:
- timestamp: 2024-02-09T01:58:09Z
type: fixed
data:
fixed-version: 0.9_rc1-r0
- id: CGA-vq95-vcgf-2j38
aliases:
- CVE-2023-38473
- GHSA-5qm6-j92f-79jp
events:
- timestamp: 2024-02-09T01:58:56Z
type: fixed
data:
fixed-version: 0.9_rc1-r0
- id: CGA-wh9g-9xfr-658j
aliases:
- CVE-2021-26720
- GHSA-jhxr-wvf5-hrp6
events:
- timestamp: 2023-06-20T14:47:42Z
type: detection
data:
type: manual
- timestamp: 2023-06-20T16:14:51Z
type: false-positive-determination
data:
type: component-vulnerability-mismatch
note: The CVE is only present in a Debian-specific packaging script.