ALT Vulnerability

This commit is contained in:
Иван Пепеляев 2024-05-02 15:02:15 +00:00
parent 0f9ca6c802
commit bf74719bcc
15 changed files with 681 additions and 15 deletions

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

View File

@ -0,0 +1,106 @@
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20247114",
"Version": "oval:org.altlinux.errata:def:20247114",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-7114: package `ds4drv` update to version 0.5.1-alt3.gitbe7327f",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-7114",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-7114",
"Source": "ALTPU"
}
],
"Description": "This update upgrades ds4drv to version 0.5.1-alt3.gitbe7327f. \nSecurity Fix(es):\n\n * #45143: Не запускается.\n\n * #50015: Не запускается из-за дубля настроек",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-05-02"
},
"Updated": {
"Date": "2024-05-02"
},
"BDUs": null,
"Bugzilla": [
{
"ID": "45143",
"Href": "https://bugzilla.altlinux.org/45143",
"Data": "Не запускается."
},
{
"ID": "50015",
"Href": "https://bugzilla.altlinux.org/50015",
"Data": "Не запускается из-за дубля настроек"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20247114001",
"Comment": "ds4drv is earlier than 0:0.5.1-alt3.gitbe7327f"
}
]
}
]
}
}
]
}

View File

@ -0,0 +1,34 @@
{
"TextFileContent54Objects": [
{
"ID": "oval:org.altlinux.errata:obj:2001",
"Version": "1",
"Comment": "Evaluate `/etc/os-release` file content",
"Path": {
"Datatype": "string",
"Text": "/etc"
},
"Filepath": {
"Datatype": "string",
"Text": "os-release"
},
"Pattern": {
"Datatype": "string",
"Operation": "pattern match",
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
},
"Instance": {
"Datatype": "int",
"Text": "1"
}
}
],
"RPMInfoObjects": [
{
"ID": "oval:org.altlinux.errata:obj:20247114001",
"Version": "1",
"Comment": "ds4drv is installed",
"Name": "ds4drv"
}
]
}

View File

@ -0,0 +1,23 @@
{
"TextFileContent54State": [
{
"ID": "oval:org.altlinux.errata:ste:2001",
"Version": "1",
"Text": {}
}
],
"RPMInfoStates": [
{
"ID": "oval:org.altlinux.errata:ste:20247114001",
"Version": "1",
"Comment": "package EVR is earlier than 0:0.5.1-alt3.gitbe7327f",
"Arch": {},
"EVR": {
"Text": "0:0.5.1-alt3.gitbe7327f",
"Datatype": "evr_string",
"Operation": "less than"
},
"Subexpression": {}
}
]
}

View File

@ -0,0 +1,30 @@
{
"TextFileContent54Tests": [
{
"ID": "oval:org.altlinux.errata:tst:2001",
"Version": "1",
"Check": "all",
"Comment": "ALT Linux based on branch 'p10' must be installed",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:2001"
}
}
],
"RPMInfoTests": [
{
"ID": "oval:org.altlinux.errata:tst:20247114001",
"Version": "1",
"Check": "all",
"Comment": "ds4drv is earlier than 0:0.5.1-alt3.gitbe7327f",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247114001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247114001"
}
}
]
}

View File

@ -0,0 +1,105 @@
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20247301",
"Version": "oval:org.altlinux.errata:def:20247301",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-7301: package `ash` update to version 0.5.8-alt1.2e5842258.p10.1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-7301",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-7301",
"Source": "ALTPU"
}
],
"Description": "This update upgrades ash to version 0.5.8-alt1.2e5842258.p10.1. \nSecurity Fix(es):\n\n * #50148: ash и beanshell конфликтуют по файлам",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-05-02"
},
"Updated": {
"Date": "2024-05-02"
},
"BDUs": null,
"Bugzilla": [
{
"ID": "50148",
"Href": "https://bugzilla.altlinux.org/50148",
"Data": "ash и beanshell конфликтуют по файлам"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20247301001",
"Comment": "ash is earlier than 0:0.5.8-alt1.2e5842258.p10.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247301002",
"Comment": "ash-static is earlier than 0:0.5.8-alt1.2e5842258.p10.1"
}
]
}
]
}
}
]
}

View File

@ -0,0 +1,40 @@
{
"TextFileContent54Objects": [
{
"ID": "oval:org.altlinux.errata:obj:2001",
"Version": "1",
"Comment": "Evaluate `/etc/os-release` file content",
"Path": {
"Datatype": "string",
"Text": "/etc"
},
"Filepath": {
"Datatype": "string",
"Text": "os-release"
},
"Pattern": {
"Datatype": "string",
"Operation": "pattern match",
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
},
"Instance": {
"Datatype": "int",
"Text": "1"
}
}
],
"RPMInfoObjects": [
{
"ID": "oval:org.altlinux.errata:obj:20247301001",
"Version": "1",
"Comment": "ash is installed",
"Name": "ash"
},
{
"ID": "oval:org.altlinux.errata:obj:20247301002",
"Version": "1",
"Comment": "ash-static is installed",
"Name": "ash-static"
}
]
}

View File

@ -0,0 +1,23 @@
{
"TextFileContent54State": [
{
"ID": "oval:org.altlinux.errata:ste:2001",
"Version": "1",
"Text": {}
}
],
"RPMInfoStates": [
{
"ID": "oval:org.altlinux.errata:ste:20247301001",
"Version": "1",
"Comment": "package EVR is earlier than 0:0.5.8-alt1.2e5842258.p10.1",
"Arch": {},
"EVR": {
"Text": "0:0.5.8-alt1.2e5842258.p10.1",
"Datatype": "evr_string",
"Operation": "less than"
},
"Subexpression": {}
}
]
}

View File

@ -0,0 +1,42 @@
{
"TextFileContent54Tests": [
{
"ID": "oval:org.altlinux.errata:tst:2001",
"Version": "1",
"Check": "all",
"Comment": "ALT Linux based on branch 'p10' must be installed",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:2001"
}
}
],
"RPMInfoTests": [
{
"ID": "oval:org.altlinux.errata:tst:20247301001",
"Version": "1",
"Check": "all",
"Comment": "ash is earlier than 0:0.5.8-alt1.2e5842258.p10.1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247301001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247301001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20247301002",
"Version": "1",
"Check": "all",
"Comment": "ash-static is earlier than 0:0.5.8-alt1.2e5842258.p10.1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247301002"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247301001"
}
}
]
}

View File

@ -0,0 +1,131 @@
{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20247305",
"Version": "oval:org.altlinux.errata:def:20247305",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-7305: package `glpi` update to version 10.0.15-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-7305",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-7305",
"Source": "ALTPU"
},
{
"RefID": "BDU:2024-03309",
"RefURL": "https://bdu.fstec.ru/vul/2024-03309",
"Source": "BDU"
},
{
"RefID": "CVE-2024-29889",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-29889",
"Source": "CVE"
},
{
"RefID": "CVE-2024-31456",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-31456",
"Source": "CVE"
}
],
"Description": "This update upgrades glpi to version 10.0.15-alt1. \nSecurity Fix(es):\n\n * BDU:2024-03309: Уязвимость системы заявок, инцидентов и инвентаризации компьютерного оборудования GLPI, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнять произвольные SQL-запросы\n\n * CVE-2024-29889: description unavailable\n\n * CVE-2024-31456: description unavailable",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-05-02"
},
"Updated": {
"Date": "2024-05-02"
},
"BDUs": [
{
"ID": "BDU:2024-03309",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-89",
"Href": "https://bdu.fstec.ru/vul/2024-03309",
"Impact": "Critical",
"Public": "20240424"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20247305001",
"Comment": "glpi is earlier than 0:10.0.15-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247305002",
"Comment": "glpi-apache2 is earlier than 0:10.0.15-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247305003",
"Comment": "glpi-php8.1 is earlier than 0:10.0.15-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247305004",
"Comment": "glpi-php8.2 is earlier than 0:10.0.15-alt1"
}
]
}
]
}
}
]
}

View File

@ -0,0 +1,52 @@
{
"TextFileContent54Objects": [
{
"ID": "oval:org.altlinux.errata:obj:2001",
"Version": "1",
"Comment": "Evaluate `/etc/os-release` file content",
"Path": {
"Datatype": "string",
"Text": "/etc"
},
"Filepath": {
"Datatype": "string",
"Text": "os-release"
},
"Pattern": {
"Datatype": "string",
"Operation": "pattern match",
"Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*"
},
"Instance": {
"Datatype": "int",
"Text": "1"
}
}
],
"RPMInfoObjects": [
{
"ID": "oval:org.altlinux.errata:obj:20247305001",
"Version": "1",
"Comment": "glpi is installed",
"Name": "glpi"
},
{
"ID": "oval:org.altlinux.errata:obj:20247305002",
"Version": "1",
"Comment": "glpi-apache2 is installed",
"Name": "glpi-apache2"
},
{
"ID": "oval:org.altlinux.errata:obj:20247305003",
"Version": "1",
"Comment": "glpi-php8.1 is installed",
"Name": "glpi-php8.1"
},
{
"ID": "oval:org.altlinux.errata:obj:20247305004",
"Version": "1",
"Comment": "glpi-php8.2 is installed",
"Name": "glpi-php8.2"
}
]
}

View File

@ -0,0 +1,23 @@
{
"TextFileContent54State": [
{
"ID": "oval:org.altlinux.errata:ste:2001",
"Version": "1",
"Text": {}
}
],
"RPMInfoStates": [
{
"ID": "oval:org.altlinux.errata:ste:20247305001",
"Version": "1",
"Comment": "package EVR is earlier than 0:10.0.15-alt1",
"Arch": {},
"EVR": {
"Text": "0:10.0.15-alt1",
"Datatype": "evr_string",
"Operation": "less than"
},
"Subexpression": {}
}
]
}

View File

@ -0,0 +1,66 @@
{
"TextFileContent54Tests": [
{
"ID": "oval:org.altlinux.errata:tst:2001",
"Version": "1",
"Check": "all",
"Comment": "ALT Linux based on branch 'p10' must be installed",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:2001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:2001"
}
}
],
"RPMInfoTests": [
{
"ID": "oval:org.altlinux.errata:tst:20247305001",
"Version": "1",
"Check": "all",
"Comment": "glpi is earlier than 0:10.0.15-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247305001"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247305001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20247305002",
"Version": "1",
"Check": "all",
"Comment": "glpi-apache2 is earlier than 0:10.0.15-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247305002"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247305001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20247305003",
"Version": "1",
"Check": "all",
"Comment": "glpi-php8.1 is earlier than 0:10.0.15-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247305003"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247305001"
}
},
{
"ID": "oval:org.altlinux.errata:tst:20247305004",
"Version": "1",
"Check": "all",
"Comment": "glpi-php8.2 is earlier than 0:10.0.15-alt1",
"Object": {
"ObjectRef": "oval:org.altlinux.errata:obj:20247305004"
},
"State": {
"StateRef": "oval:org.altlinux.errata:ste:20247305001"
}
}
]
}

File diff suppressed because one or more lines are too long