143 lines
5.8 KiB
JSON
Raw Normal View History

2024-12-12 21:07:30 +00:00
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20212192",
"Version": "oval:org.altlinux.errata:def:20212192",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-2192: package `php8.0` update to version 8.0.8-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-2192",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2192",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-03559",
"RefURL": "https://bdu.fstec.ru/vul/2021-03559",
"Source": "BDU"
},
{
"RefID": "BDU:2021-03703",
"RefURL": "https://bdu.fstec.ru/vul/2021-03703",
"Source": "BDU"
},
{
"RefID": "CVE-2021-21704",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-21704",
"Source": "CVE"
},
{
"RefID": "CVE-2021-21705",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-21705",
"Source": "CVE"
}
],
"Description": "This update upgrades php8.0 to version 8.0.8-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03559: Уязвимость модуля pdo_firebase интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-03703: Уязвимость функции php_url_parse_ex() интерпретатора языка программирования PHP, позволяющая нарушителю осуществить SSRF-атаку\n\n * CVE-2021-21704: In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.\n\n * CVE-2021-21705: In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-07-12"
},
"Updated": {
"Date": "2021-07-12"
},
"BDUs": [
{
"ID": "BDU:2021-03559",
"CVSS": "AV:N/AC:H/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-20",
"Href": "https://bdu.fstec.ru/vul/2021-03559",
"Impact": "Low",
"Public": "20210629"
},
{
"ID": "BDU:2021-03703",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-20, CWE-918",
"Href": "https://bdu.fstec.ru/vul/2021-03703",
"Impact": "Low",
"Public": "20210702"
}
],
"CVEs": [
{
"ID": "CVE-2021-21704",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-21704",
"Impact": "Low",
"Public": "20211004"
},
{
"ID": "CVE-2021-21705",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-21705",
"Impact": "Low",
"Public": "20211004"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20212192001",
"Comment": "php8.0 is earlier than 0:8.0.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212192002",
"Comment": "php8.0-devel is earlier than 0:8.0.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212192003",
"Comment": "php8.0-libs is earlier than 0:8.0.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212192004",
"Comment": "php8.0-mysqlnd is earlier than 0:8.0.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212192005",
"Comment": "rpm-build-php8.0-version is earlier than 0:8.0.8-alt1"
}
]
}
]
}
}
]
}