ALT Vulnerability
This commit is contained in:
parent
e091deee9f
commit
8148074038
90
oval/p10/ALT-PU-2025-1312/definitions.json
Normal file
90
oval/p10/ALT-PU-2025-1312/definitions.json
Normal file
@ -0,0 +1,90 @@
|
||||
{
|
||||
"Definition": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:def:20251312",
|
||||
"Version": "oval:org.altlinux.errata:def:20251312",
|
||||
"Class": "patch",
|
||||
"Metadata": {
|
||||
"Title": "ALT-PU-2025-1312: package `veyon` update to version 4.9.1-alt0.p10.1",
|
||||
"AffectedList": [
|
||||
{
|
||||
"Family": "unix",
|
||||
"Platforms": [
|
||||
"ALT Linux branch p10"
|
||||
],
|
||||
"Products": [
|
||||
"ALT Server",
|
||||
"ALT Virtualization Server",
|
||||
"ALT Workstation",
|
||||
"ALT Workstation K",
|
||||
"ALT Education",
|
||||
"Simply Linux",
|
||||
"Starterkit",
|
||||
"ALT Container"
|
||||
]
|
||||
}
|
||||
],
|
||||
"References": [
|
||||
{
|
||||
"RefID": "ALT-PU-2025-1312",
|
||||
"RefURL": "https://errata.altlinux.org/ALT-PU-2025-1312",
|
||||
"Source": "ALTPU"
|
||||
}
|
||||
],
|
||||
"Description": "This update upgrades veyon to version 4.9.1-alt0.p10.1. \nSecurity Fix(es):\n\n * #51649: veyon не запускается с ошибкой CryptoCore: RSA not supported!",
|
||||
"Advisory": {
|
||||
"From": "errata.altlinux.org",
|
||||
"Severity": "Low",
|
||||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||||
"Issued": {
|
||||
"Date": "2025-02-01"
|
||||
},
|
||||
"Updated": {
|
||||
"Date": "2025-02-01"
|
||||
},
|
||||
"BDUs": null,
|
||||
"Bugzilla": [
|
||||
{
|
||||
"ID": "51649",
|
||||
"Href": "https://bugzilla.altlinux.org/51649",
|
||||
"Data": "veyon не запускается с ошибкой CryptoCore: RSA not supported!"
|
||||
}
|
||||
],
|
||||
"AffectedCPEs": {
|
||||
"CPEs": [
|
||||
"cpe:/o:alt:kworkstation:10",
|
||||
"cpe:/o:alt:workstation:10",
|
||||
"cpe:/o:alt:server:10",
|
||||
"cpe:/o:alt:server-v:10",
|
||||
"cpe:/o:alt:education:10",
|
||||
"cpe:/o:alt:slinux:10",
|
||||
"cpe:/o:alt:starterkit:10",
|
||||
"cpe:/o:alt:starterkit:p10",
|
||||
"cpe:/o:alt:container:10"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"Criteria": {
|
||||
"Operator": "AND",
|
||||
"Criterions": [
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:2001",
|
||||
"Comment": "ALT Linux must be installed"
|
||||
}
|
||||
],
|
||||
"Criterias": [
|
||||
{
|
||||
"Operator": "OR",
|
||||
"Criterions": [
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20251312001",
|
||||
"Comment": "veyon is earlier than 0:4.9.1-alt0.p10.1"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
34
oval/p10/ALT-PU-2025-1312/objects.json
Normal file
34
oval/p10/ALT-PU-2025-1312/objects.json
Normal file
@ -0,0 +1,34 @@
|
||||
{
|
||||
"TextFileContent54Objects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:2001",
|
||||
"Version": "1",
|
||||
"Comment": "Evaluate `/etc/os-release` file content",
|
||||
"Path": {
|
||||
"Datatype": "string",
|
||||
"Text": "/etc"
|
||||
},
|
||||
"Filepath": {
|
||||
"Datatype": "string",
|
||||
"Text": "os-release"
|
||||
},
|
||||
"Pattern": {
|
||||
"Datatype": "string",
|
||||
"Operation": "pattern match",
|
||||
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
|
||||
},
|
||||
"Instance": {
|
||||
"Datatype": "int",
|
||||
"Text": "1"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoObjects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20251312001",
|
||||
"Version": "1",
|
||||
"Comment": "veyon is installed",
|
||||
"Name": "veyon"
|
||||
}
|
||||
]
|
||||
}
|
23
oval/p10/ALT-PU-2025-1312/states.json
Normal file
23
oval/p10/ALT-PU-2025-1312/states.json
Normal file
@ -0,0 +1,23 @@
|
||||
{
|
||||
"TextFileContent54State": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:2001",
|
||||
"Version": "1",
|
||||
"Text": {}
|
||||
}
|
||||
],
|
||||
"RPMInfoStates": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:20251312001",
|
||||
"Version": "1",
|
||||
"Comment": "package EVR is earlier than 0:4.9.1-alt0.p10.1",
|
||||
"Arch": {},
|
||||
"EVR": {
|
||||
"Text": "0:4.9.1-alt0.p10.1",
|
||||
"Datatype": "evr_string",
|
||||
"Operation": "less than"
|
||||
},
|
||||
"Subexpression": {}
|
||||
}
|
||||
]
|
||||
}
|
30
oval/p10/ALT-PU-2025-1312/tests.json
Normal file
30
oval/p10/ALT-PU-2025-1312/tests.json
Normal file
@ -0,0 +1,30 @@
|
||||
{
|
||||
"TextFileContent54Tests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:2001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "ALT Linux based on branch 'p10' must be installed",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:2001"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoTests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20251312001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "veyon is earlier than 0:4.9.1-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20251312001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20251312001"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
240
oval/p10/ALT-PU-2025-2137/definitions.json
Normal file
240
oval/p10/ALT-PU-2025-2137/definitions.json
Normal file
File diff suppressed because one or more lines are too long
46
oval/p10/ALT-PU-2025-2137/objects.json
Normal file
46
oval/p10/ALT-PU-2025-2137/objects.json
Normal file
@ -0,0 +1,46 @@
|
||||
{
|
||||
"TextFileContent54Objects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:2001",
|
||||
"Version": "1",
|
||||
"Comment": "Evaluate `/etc/os-release` file content",
|
||||
"Path": {
|
||||
"Datatype": "string",
|
||||
"Text": "/etc"
|
||||
},
|
||||
"Filepath": {
|
||||
"Datatype": "string",
|
||||
"Text": "os-release"
|
||||
},
|
||||
"Pattern": {
|
||||
"Datatype": "string",
|
||||
"Operation": "pattern match",
|
||||
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
|
||||
},
|
||||
"Instance": {
|
||||
"Datatype": "int",
|
||||
"Text": "1"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoObjects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252137001",
|
||||
"Version": "1",
|
||||
"Comment": "nextcloud is installed",
|
||||
"Name": "nextcloud"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252137002",
|
||||
"Version": "1",
|
||||
"Comment": "nextcloud-apache2 is installed",
|
||||
"Name": "nextcloud-apache2"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252137003",
|
||||
"Version": "1",
|
||||
"Comment": "nextcloud-nginx is installed",
|
||||
"Name": "nextcloud-nginx"
|
||||
}
|
||||
]
|
||||
}
|
23
oval/p10/ALT-PU-2025-2137/states.json
Normal file
23
oval/p10/ALT-PU-2025-2137/states.json
Normal file
@ -0,0 +1,23 @@
|
||||
{
|
||||
"TextFileContent54State": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:2001",
|
||||
"Version": "1",
|
||||
"Text": {}
|
||||
}
|
||||
],
|
||||
"RPMInfoStates": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:20252137001",
|
||||
"Version": "1",
|
||||
"Comment": "package EVR is earlier than 0:30.0.5-alt1",
|
||||
"Arch": {},
|
||||
"EVR": {
|
||||
"Text": "0:30.0.5-alt1",
|
||||
"Datatype": "evr_string",
|
||||
"Operation": "less than"
|
||||
},
|
||||
"Subexpression": {}
|
||||
}
|
||||
]
|
||||
}
|
54
oval/p10/ALT-PU-2025-2137/tests.json
Normal file
54
oval/p10/ALT-PU-2025-2137/tests.json
Normal file
@ -0,0 +1,54 @@
|
||||
{
|
||||
"TextFileContent54Tests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:2001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "ALT Linux based on branch 'p10' must be installed",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:2001"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoTests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252137001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "nextcloud is earlier than 0:30.0.5-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252137001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252137001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252137002",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "nextcloud-apache2 is earlier than 0:30.0.5-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252137002"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252137001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252137003",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "nextcloud-nginx is earlier than 0:30.0.5-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252137003"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252137001"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
120
oval/p10/ALT-PU-2025-2143/definitions.json
Normal file
120
oval/p10/ALT-PU-2025-2143/definitions.json
Normal file
@ -0,0 +1,120 @@
|
||||
{
|
||||
"Definition": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:def:20252143",
|
||||
"Version": "oval:org.altlinux.errata:def:20252143",
|
||||
"Class": "patch",
|
||||
"Metadata": {
|
||||
"Title": "ALT-PU-2025-2143: package `java-21-openjdk` update to version 21.0.6.0.7-alt0.p10.1",
|
||||
"AffectedList": [
|
||||
{
|
||||
"Family": "unix",
|
||||
"Platforms": [
|
||||
"ALT Linux branch p10"
|
||||
],
|
||||
"Products": [
|
||||
"ALT Server",
|
||||
"ALT Virtualization Server",
|
||||
"ALT Workstation",
|
||||
"ALT Workstation K",
|
||||
"ALT Education",
|
||||
"Simply Linux",
|
||||
"Starterkit",
|
||||
"ALT Container"
|
||||
]
|
||||
}
|
||||
],
|
||||
"References": [
|
||||
{
|
||||
"RefID": "ALT-PU-2025-2143",
|
||||
"RefURL": "https://errata.altlinux.org/ALT-PU-2025-2143",
|
||||
"Source": "ALTPU"
|
||||
},
|
||||
{
|
||||
"RefID": "CVE-2025-21502",
|
||||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2025-21502",
|
||||
"Source": "CVE"
|
||||
}
|
||||
],
|
||||
"Description": "This update upgrades java-21-openjdk to version 21.0.6.0.7-alt0.p10.1. \nSecurity Fix(es):\n\n * CVE-2025-21502: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
|
||||
"Advisory": {
|
||||
"From": "errata.altlinux.org",
|
||||
"Severity": "Low",
|
||||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||||
"Issued": {
|
||||
"Date": "2025-02-01"
|
||||
},
|
||||
"Updated": {
|
||||
"Date": "2025-02-01"
|
||||
},
|
||||
"BDUs": null,
|
||||
"CVEs": [
|
||||
{
|
||||
"ID": "CVE-2025-21502",
|
||||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2025-21502",
|
||||
"Impact": "None",
|
||||
"Public": "20250121"
|
||||
}
|
||||
],
|
||||
"AffectedCPEs": {
|
||||
"CPEs": [
|
||||
"cpe:/o:alt:kworkstation:10",
|
||||
"cpe:/o:alt:workstation:10",
|
||||
"cpe:/o:alt:server:10",
|
||||
"cpe:/o:alt:server-v:10",
|
||||
"cpe:/o:alt:education:10",
|
||||
"cpe:/o:alt:slinux:10",
|
||||
"cpe:/o:alt:starterkit:10",
|
||||
"cpe:/o:alt:starterkit:p10",
|
||||
"cpe:/o:alt:container:10"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"Criteria": {
|
||||
"Operator": "AND",
|
||||
"Criterions": [
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:2001",
|
||||
"Comment": "ALT Linux must be installed"
|
||||
}
|
||||
],
|
||||
"Criterias": [
|
||||
{
|
||||
"Operator": "OR",
|
||||
"Criterions": [
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143001",
|
||||
"Comment": "java-21-openjdk is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143002",
|
||||
"Comment": "java-21-openjdk-demo is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143003",
|
||||
"Comment": "java-21-openjdk-devel is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143004",
|
||||
"Comment": "java-21-openjdk-headless is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143005",
|
||||
"Comment": "java-21-openjdk-javadoc is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143006",
|
||||
"Comment": "java-21-openjdk-jmods is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252143007",
|
||||
"Comment": "java-21-openjdk-sources is earlier than 0:21.0.6.0.7-alt0.p10.1"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
70
oval/p10/ALT-PU-2025-2143/objects.json
Normal file
70
oval/p10/ALT-PU-2025-2143/objects.json
Normal file
@ -0,0 +1,70 @@
|
||||
{
|
||||
"TextFileContent54Objects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:2001",
|
||||
"Version": "1",
|
||||
"Comment": "Evaluate `/etc/os-release` file content",
|
||||
"Path": {
|
||||
"Datatype": "string",
|
||||
"Text": "/etc"
|
||||
},
|
||||
"Filepath": {
|
||||
"Datatype": "string",
|
||||
"Text": "os-release"
|
||||
},
|
||||
"Pattern": {
|
||||
"Datatype": "string",
|
||||
"Operation": "pattern match",
|
||||
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
|
||||
},
|
||||
"Instance": {
|
||||
"Datatype": "int",
|
||||
"Text": "1"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoObjects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143001",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk is installed",
|
||||
"Name": "java-21-openjdk"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143002",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk-demo is installed",
|
||||
"Name": "java-21-openjdk-demo"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143003",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk-devel is installed",
|
||||
"Name": "java-21-openjdk-devel"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143004",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk-headless is installed",
|
||||
"Name": "java-21-openjdk-headless"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143005",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk-javadoc is installed",
|
||||
"Name": "java-21-openjdk-javadoc"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143006",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk-jmods is installed",
|
||||
"Name": "java-21-openjdk-jmods"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252143007",
|
||||
"Version": "1",
|
||||
"Comment": "java-21-openjdk-sources is installed",
|
||||
"Name": "java-21-openjdk-sources"
|
||||
}
|
||||
]
|
||||
}
|
23
oval/p10/ALT-PU-2025-2143/states.json
Normal file
23
oval/p10/ALT-PU-2025-2143/states.json
Normal file
@ -0,0 +1,23 @@
|
||||
{
|
||||
"TextFileContent54State": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:2001",
|
||||
"Version": "1",
|
||||
"Text": {}
|
||||
}
|
||||
],
|
||||
"RPMInfoStates": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:20252143001",
|
||||
"Version": "1",
|
||||
"Comment": "package EVR is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Arch": {},
|
||||
"EVR": {
|
||||
"Text": "0:21.0.6.0.7-alt0.p10.1",
|
||||
"Datatype": "evr_string",
|
||||
"Operation": "less than"
|
||||
},
|
||||
"Subexpression": {}
|
||||
}
|
||||
]
|
||||
}
|
102
oval/p10/ALT-PU-2025-2143/tests.json
Normal file
102
oval/p10/ALT-PU-2025-2143/tests.json
Normal file
@ -0,0 +1,102 @@
|
||||
{
|
||||
"TextFileContent54Tests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:2001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "ALT Linux based on branch 'p10' must be installed",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:2001"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoTests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143002",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk-demo is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143002"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143003",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk-devel is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143003"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143004",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk-headless is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143004"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143005",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk-javadoc is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143005"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143006",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk-jmods is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143006"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252143007",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-21-openjdk-sources is earlier than 0:21.0.6.0.7-alt0.p10.1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252143007"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252143001"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
124
oval/p10/ALT-PU-2025-2145/definitions.json
Normal file
124
oval/p10/ALT-PU-2025-2145/definitions.json
Normal file
@ -0,0 +1,124 @@
|
||||
{
|
||||
"Definition": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:def:20252145",
|
||||
"Version": "oval:org.altlinux.errata:def:20252145",
|
||||
"Class": "patch",
|
||||
"Metadata": {
|
||||
"Title": "ALT-PU-2025-2145: package `java-17-openjdk` update to version 17.0.14.0.7-alt1",
|
||||
"AffectedList": [
|
||||
{
|
||||
"Family": "unix",
|
||||
"Platforms": [
|
||||
"ALT Linux branch p10"
|
||||
],
|
||||
"Products": [
|
||||
"ALT Server",
|
||||
"ALT Virtualization Server",
|
||||
"ALT Workstation",
|
||||
"ALT Workstation K",
|
||||
"ALT Education",
|
||||
"Simply Linux",
|
||||
"Starterkit",
|
||||
"ALT Container"
|
||||
]
|
||||
}
|
||||
],
|
||||
"References": [
|
||||
{
|
||||
"RefID": "ALT-PU-2025-2145",
|
||||
"RefURL": "https://errata.altlinux.org/ALT-PU-2025-2145",
|
||||
"Source": "ALTPU"
|
||||
},
|
||||
{
|
||||
"RefID": "CVE-2025-21502",
|
||||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2025-21502",
|
||||
"Source": "CVE"
|
||||
}
|
||||
],
|
||||
"Description": "This update upgrades java-17-openjdk to version 17.0.14.0.7-alt1. \nSecurity Fix(es):\n\n * CVE-2025-21502: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
|
||||
"Advisory": {
|
||||
"From": "errata.altlinux.org",
|
||||
"Severity": "Low",
|
||||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||||
"Issued": {
|
||||
"Date": "2025-02-02"
|
||||
},
|
||||
"Updated": {
|
||||
"Date": "2025-02-02"
|
||||
},
|
||||
"BDUs": null,
|
||||
"CVEs": [
|
||||
{
|
||||
"ID": "CVE-2025-21502",
|
||||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2025-21502",
|
||||
"Impact": "None",
|
||||
"Public": "20250121"
|
||||
}
|
||||
],
|
||||
"AffectedCPEs": {
|
||||
"CPEs": [
|
||||
"cpe:/o:alt:kworkstation:10",
|
||||
"cpe:/o:alt:workstation:10",
|
||||
"cpe:/o:alt:server:10",
|
||||
"cpe:/o:alt:server-v:10",
|
||||
"cpe:/o:alt:education:10",
|
||||
"cpe:/o:alt:slinux:10",
|
||||
"cpe:/o:alt:starterkit:10",
|
||||
"cpe:/o:alt:starterkit:p10",
|
||||
"cpe:/o:alt:container:10"
|
||||
]
|
||||
}
|
||||
}
|
||||
},
|
||||
"Criteria": {
|
||||
"Operator": "AND",
|
||||
"Criterions": [
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:2001",
|
||||
"Comment": "ALT Linux must be installed"
|
||||
}
|
||||
],
|
||||
"Criterias": [
|
||||
{
|
||||
"Operator": "OR",
|
||||
"Criterions": [
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145001",
|
||||
"Comment": "java-17-openjdk is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145002",
|
||||
"Comment": "java-17-openjdk-demo is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145003",
|
||||
"Comment": "java-17-openjdk-devel is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145004",
|
||||
"Comment": "java-17-openjdk-headless is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145005",
|
||||
"Comment": "java-17-openjdk-javadoc is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145006",
|
||||
"Comment": "java-17-openjdk-javadoc-zip is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145007",
|
||||
"Comment": "java-17-openjdk-jmods is earlier than 0:17.0.14.0.7-alt1"
|
||||
},
|
||||
{
|
||||
"TestRef": "oval:org.altlinux.errata:tst:20252145008",
|
||||
"Comment": "java-17-openjdk-src is earlier than 0:17.0.14.0.7-alt1"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
76
oval/p10/ALT-PU-2025-2145/objects.json
Normal file
76
oval/p10/ALT-PU-2025-2145/objects.json
Normal file
@ -0,0 +1,76 @@
|
||||
{
|
||||
"TextFileContent54Objects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:2001",
|
||||
"Version": "1",
|
||||
"Comment": "Evaluate `/etc/os-release` file content",
|
||||
"Path": {
|
||||
"Datatype": "string",
|
||||
"Text": "/etc"
|
||||
},
|
||||
"Filepath": {
|
||||
"Datatype": "string",
|
||||
"Text": "os-release"
|
||||
},
|
||||
"Pattern": {
|
||||
"Datatype": "string",
|
||||
"Operation": "pattern match",
|
||||
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
|
||||
},
|
||||
"Instance": {
|
||||
"Datatype": "int",
|
||||
"Text": "1"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoObjects": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145001",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk is installed",
|
||||
"Name": "java-17-openjdk"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145002",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-demo is installed",
|
||||
"Name": "java-17-openjdk-demo"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145003",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-devel is installed",
|
||||
"Name": "java-17-openjdk-devel"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145004",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-headless is installed",
|
||||
"Name": "java-17-openjdk-headless"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145005",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-javadoc is installed",
|
||||
"Name": "java-17-openjdk-javadoc"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145006",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-javadoc-zip is installed",
|
||||
"Name": "java-17-openjdk-javadoc-zip"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145007",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-jmods is installed",
|
||||
"Name": "java-17-openjdk-jmods"
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:obj:20252145008",
|
||||
"Version": "1",
|
||||
"Comment": "java-17-openjdk-src is installed",
|
||||
"Name": "java-17-openjdk-src"
|
||||
}
|
||||
]
|
||||
}
|
23
oval/p10/ALT-PU-2025-2145/states.json
Normal file
23
oval/p10/ALT-PU-2025-2145/states.json
Normal file
@ -0,0 +1,23 @@
|
||||
{
|
||||
"TextFileContent54State": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:2001",
|
||||
"Version": "1",
|
||||
"Text": {}
|
||||
}
|
||||
],
|
||||
"RPMInfoStates": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:ste:20252145001",
|
||||
"Version": "1",
|
||||
"Comment": "package EVR is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Arch": {},
|
||||
"EVR": {
|
||||
"Text": "0:17.0.14.0.7-alt1",
|
||||
"Datatype": "evr_string",
|
||||
"Operation": "less than"
|
||||
},
|
||||
"Subexpression": {}
|
||||
}
|
||||
]
|
||||
}
|
114
oval/p10/ALT-PU-2025-2145/tests.json
Normal file
114
oval/p10/ALT-PU-2025-2145/tests.json
Normal file
@ -0,0 +1,114 @@
|
||||
{
|
||||
"TextFileContent54Tests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:2001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "ALT Linux based on branch 'p10' must be installed",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:2001"
|
||||
}
|
||||
}
|
||||
],
|
||||
"RPMInfoTests": [
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145001",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145001"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145002",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-demo is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145002"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145003",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-devel is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145003"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145004",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-headless is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145004"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145005",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-javadoc is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145005"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145006",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-javadoc-zip is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145006"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145007",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-jmods is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145007"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
},
|
||||
{
|
||||
"ID": "oval:org.altlinux.errata:tst:20252145008",
|
||||
"Version": "1",
|
||||
"Check": "all",
|
||||
"Comment": "java-17-openjdk-src is earlier than 0:17.0.14.0.7-alt1",
|
||||
"Object": {
|
||||
"ObjectRef": "oval:org.altlinux.errata:obj:20252145008"
|
||||
},
|
||||
"State": {
|
||||
"StateRef": "oval:org.altlinux.errata:ste:20252145001"
|
||||
}
|
||||
}
|
||||
]
|
||||
}
|
Loading…
x
Reference in New Issue
Block a user