2024-06-28 16:17:52 +03:00
{
"Definition" : [
{
"ID" : "oval:org.altlinux.errata:def:20181880" ,
"Version" : "oval:org.altlinux.errata:def:20181880" ,
"Class" : "patch" ,
"Metadata" : {
"Title" : "ALT-PU-2018-1880: package `elfutils` update to version 0.171-alt1" ,
"AffectedList" : [
{
"Family" : "unix" ,
"Platforms" : [
"ALT Linux branch c10f1"
] ,
"Products" : [
"ALT SP Workstation" ,
"ALT SP Server"
]
}
] ,
"References" : [
{
"RefID" : "ALT-PU-2018-1880" ,
"RefURL" : "https://errata.altlinux.org/ALT-PU-2018-1880" ,
"Source" : "ALTPU"
} ,
{
"RefID" : "CVE-2018-8769" ,
"RefURL" : "https://nvd.nist.gov/vuln/detail/CVE-2018-8769" ,
"Source" : "CVE"
}
] ,
"Description" : "This update upgrades elfutils to version 0.171-alt1. \nSecurity Fix(es):\n\n * CVE-2018-8769: elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported." ,
"Advisory" : {
"From" : "errata.altlinux.org" ,
"Severity" : "High" ,
"Rights" : "Copyright 2024 BaseALT Ltd." ,
"Issued" : {
"Date" : "2018-06-08"
} ,
"Updated" : {
"Date" : "2018-06-08"
} ,
"BDUs" : null ,
"CVEs" : [
{
"ID" : "CVE-2018-8769" ,
"CVSS" : "AV:N/AC:M/Au:N/C:P/I:P/A:P" ,
"CVSS3" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
"CWE" : "CWE-125" ,
"Href" : "https://nvd.nist.gov/vuln/detail/CVE-2018-8769" ,
"Impact" : "High" ,
"Public" : "20180318"
}
] ,
"AffectedCPEs" : {
"CPEs" : [
"cpe:/o:alt:spworkstation:10" ,
"cpe:/o:alt:spserver:10"
]
}
}
} ,
"Criteria" : {
"Operator" : "AND" ,
"Criterions" : [
{
2024-12-13 00:07:30 +03:00
"TestRef" : "oval:org.altlinux.errata:tst:5001" ,
2024-06-28 16:17:52 +03:00
"Comment" : "ALT Linux must be installed"
}
] ,
"Criterias" : [
{
"Operator" : "OR" ,
"Criterions" : [
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880001" ,
"Comment" : "elfutils is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880002" ,
"Comment" : "elfutils-devel is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880003" ,
"Comment" : "elfutils-devel-static is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880004" ,
"Comment" : "libasm is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880005" ,
"Comment" : "libasm-devel is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880006" ,
"Comment" : "libasm-devel-static is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880007" ,
"Comment" : "libdw is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880008" ,
"Comment" : "libdw-devel is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880009" ,
"Comment" : "libdw-devel-static is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880010" ,
"Comment" : "libelf is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880011" ,
"Comment" : "libelf-devel is earlier than 0:0.171-alt1"
} ,
{
"TestRef" : "oval:org.altlinux.errata:tst:20181880012" ,
"Comment" : "libelf-devel-static is earlier than 0:0.171-alt1"
}
]
}
]
}
}
]
}