From fccff11320b33a4414bc48e7f1a1f77ebab85912 Mon Sep 17 00:00:00 2001 From: pepelyaevip Date: Sun, 24 Mar 2024 21:02:20 +0000 Subject: [PATCH] ALT Vulnerability --- oval/p10/ALT-PU-2024-3927/definitions.json | 121 +++++++++++++++++++++ oval/p10/ALT-PU-2024-3927/objects.json | 34 ++++++ oval/p10/ALT-PU-2024-3927/states.json | 23 ++++ oval/p10/ALT-PU-2024-3927/tests.json | 30 +++++ oval/p10/ALT-PU-2024-4151/definitions.json | 106 ++++++++++++++++++ oval/p10/ALT-PU-2024-4151/objects.json | 34 ++++++ oval/p10/ALT-PU-2024-4151/states.json | 23 ++++ oval/p10/ALT-PU-2024-4151/tests.json | 30 +++++ 8 files changed, 401 insertions(+) create mode 100644 oval/p10/ALT-PU-2024-3927/definitions.json create mode 100644 oval/p10/ALT-PU-2024-3927/objects.json create mode 100644 oval/p10/ALT-PU-2024-3927/states.json create mode 100644 oval/p10/ALT-PU-2024-3927/tests.json create mode 100644 oval/p10/ALT-PU-2024-4151/definitions.json create mode 100644 oval/p10/ALT-PU-2024-4151/objects.json create mode 100644 oval/p10/ALT-PU-2024-4151/states.json create mode 100644 oval/p10/ALT-PU-2024-4151/tests.json diff --git a/oval/p10/ALT-PU-2024-3927/definitions.json b/oval/p10/ALT-PU-2024-3927/definitions.json new file mode 100644 index 0000000000..0f19e0c0e6 --- /dev/null +++ b/oval/p10/ALT-PU-2024-3927/definitions.json @@ -0,0 +1,121 @@ +{ + "Definition": [ + { + "ID": "oval:org.altlinux.errata:def:20243927", + "Version": "oval:org.altlinux.errata:def:20243927", + "Class": "patch", + "Metadata": { + "Title": "ALT-PU-2024-3927: package `alterator-netinst` update to version 1.9.1-alt7", + "AffectedList": [ + { + "Family": "unix", + "Platforms": [ + "ALT Linux branch p10" + ], + "Products": [ + "ALT Server", + "ALT Virtualization Server", + "ALT Workstation", + "ALT Workstation K", + "ALT Education", + "Simply Linux", + "Starterkit" + ] + } + ], + "References": [ + { + "RefID": "ALT-PU-2024-3927", + "RefURL": "https://errata.altlinux.org/ALT-PU-2024-3927", + "Source": "ALTPU" + } + ], + "Description": "This update upgrades alterator-netinst to version 1.9.1-alt7. \nSecurity Fix(es):\n\n * #40265: Сервер сетевых установок: удалить образ -\u003e образ отображается в текущих\n\n * #45970: [FR] Крайне необходимо добавить возможность выставления опции ai для автоинсталла (сценарий установки по PXE)\n\n * #46599: Сервер сетевых установок: удалить образ -\u003e сервер не грузится\n\n * #46975: Некорректное применение настроек через alterator-netinst: невозможно удалить строки, связанные с подключением по VNC\n\n * #49051: Нет возможности выбрать вариант загрузки, пустое значение", + "Advisory": { + "From": "errata.altlinux.org", + "Severity": "Low", + "Rights": "Copyright 2024 BaseALT Ltd.", + "Issued": { + "Date": "2024-03-24" + }, + "Updated": { + "Date": "2024-03-24" + }, + "bdu": null, + "Bugzilla": [ + { + "Id": "40265", + "Href": "https://bugzilla.altlinux.org/40265", + "Data": "Сервер сетевых установок: удалить образ -\u003e образ отображается в текущих" + }, + { + "Id": "45970", + "Href": "https://bugzilla.altlinux.org/45970", + "Data": "[FR] Крайне необходимо добавить возможность выставления опции ai для автоинсталла (сценарий установки по PXE)" + }, + { + "Id": "46599", + "Href": "https://bugzilla.altlinux.org/46599", + "Data": "Сервер сетевых установок: удалить образ -\u003e сервер не грузится" + }, + { + "Id": "46975", + "Href": "https://bugzilla.altlinux.org/46975", + "Data": "Некорректное применение настроек через alterator-netinst: невозможно удалить строки, связанные с подключением по VNC" + }, + { + "Id": "49051", + "Href": "https://bugzilla.altlinux.org/49051", + "Data": "Нет возможности выбрать вариант загрузки, пустое значение" + } + ], + "AffectedCpeList": { + "Cpe": [ + "cpe:/o:alt:kworkstation:10", + "cpe:/o:alt:workstation:10", + "cpe:/o:alt:server:10", + "cpe:/o:alt:server-v:10", + "cpe:/o:alt:education:10", + "cpe:/o:alt:slinux:10", + "cpe:/o:alt:starterkit:p10", + "cpe:/o:alt:kworkstation:10.1", + "cpe:/o:alt:workstation:10.1", + "cpe:/o:alt:server:10.1", + "cpe:/o:alt:server-v:10.1", + "cpe:/o:alt:education:10.1", + "cpe:/o:alt:slinux:10.1", + "cpe:/o:alt:starterkit:10.1", + "cpe:/o:alt:kworkstation:10.2", + "cpe:/o:alt:workstation:10.2", + "cpe:/o:alt:server:10.2", + "cpe:/o:alt:server-v:10.2", + "cpe:/o:alt:education:10.2", + "cpe:/o:alt:slinux:10.2", + "cpe:/o:alt:starterkit:10.2" + ] + } + } + }, + "Criteria": { + "Operator": "AND", + "Criterions": [ + { + "TestRef": "oval:org.altlinux.errata:tst:2001", + "Comment": "ALT Linux must be installed" + } + ], + "Criterias": [ + { + "Operator": "OR", + "Criterions": [ + { + "TestRef": "oval:org.altlinux.errata:tst:20243927001", + "Comment": "alterator-netinst is earlier than 0:1.9.1-alt7" + } + ] + } + ] + } + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-3927/objects.json b/oval/p10/ALT-PU-2024-3927/objects.json new file mode 100644 index 0000000000..eee71608eb --- /dev/null +++ b/oval/p10/ALT-PU-2024-3927/objects.json @@ -0,0 +1,34 @@ +{ + "TextFileContent54Objects": [ + { + "ID": "oval:org.altlinux.errata:obj:2001", + "Version": "1", + "comment": "Evaluate `/etc/os-release` file content", + "Path": { + "dataType": "string", + "Text": "/etc" + }, + "Filepath": { + "Datatype": "string", + "Text": "os-release" + }, + "Pattern": { + "Datatype": "string", + "Operation": "pattern match", + "Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*" + }, + "Instance": { + "Datatype": "int", + "Text": "1" + } + } + ], + "RpmInfoObjects": [ + { + "ID": "oval:org.altlinux.errata:obj:20243927001", + "Version": "1", + "comment": "alterator-netinst is installed", + "Name": "alterator-netinst" + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-3927/states.json b/oval/p10/ALT-PU-2024-3927/states.json new file mode 100644 index 0000000000..c748475f7f --- /dev/null +++ b/oval/p10/ALT-PU-2024-3927/states.json @@ -0,0 +1,23 @@ +{ + "TextFileContent54State": [ + { + "ID": "oval:org.altlinux.errata:ste:2001", + "Version": "1", + "Text": {} + } + ], + "RpmInfoState": [ + { + "ID": "oval:org.altlinux.errata:ste:20243927001", + "Version": "1", + "Comment": "package EVR is earlier than 0:1.9.1-alt7", + "Arch": {}, + "Evr": { + "Text": "0:1.9.1-alt7", + "Datatype": "evr_string", + "Operation": "less than" + }, + "Subexpression": {} + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-3927/tests.json b/oval/p10/ALT-PU-2024-3927/tests.json new file mode 100644 index 0000000000..4fbccd3f32 --- /dev/null +++ b/oval/p10/ALT-PU-2024-3927/tests.json @@ -0,0 +1,30 @@ +{ + "TextFileContent54Tests": [ + { + "ID": "oval:org.altlinux.errata:tst:2001", + "Version": "1", + "Check": "all", + "Comment": "ALT Linux based on branch 'p10' must be installed", + "Object": { + "ObjectRef": "oval:org.altlinux.errata:obj:2001" + }, + "State": { + "StateRef": "oval:org.altlinux.errata:ste:2001" + } + } + ], + "RPMInfoTests": [ + { + "ID": "oval:org.altlinux.errata:tst:20243927001", + "Version": "1", + "Check": "all", + "Comment": "alterator-netinst is earlier than 0:1.9.1-alt7", + "Object": { + "ObjectRef": "oval:org.altlinux.errata:obj:20243927001" + }, + "State": { + "StateRef": "oval:org.altlinux.errata:ste:20243927001" + } + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-4151/definitions.json b/oval/p10/ALT-PU-2024-4151/definitions.json new file mode 100644 index 0000000000..69cd862e0d --- /dev/null +++ b/oval/p10/ALT-PU-2024-4151/definitions.json @@ -0,0 +1,106 @@ +{ + "Definition": [ + { + "ID": "oval:org.altlinux.errata:def:20244151", + "Version": "oval:org.altlinux.errata:def:20244151", + "Class": "patch", + "Metadata": { + "Title": "ALT-PU-2024-4151: package `uget` update to version 2.2.3-alt2", + "AffectedList": [ + { + "Family": "unix", + "Platforms": [ + "ALT Linux branch p10" + ], + "Products": [ + "ALT Server", + "ALT Virtualization Server", + "ALT Workstation", + "ALT Workstation K", + "ALT Education", + "Simply Linux", + "Starterkit" + ] + } + ], + "References": [ + { + "RefID": "ALT-PU-2024-4151", + "RefURL": "https://errata.altlinux.org/ALT-PU-2024-4151", + "Source": "ALTPU" + } + ], + "Description": "This update upgrades uget to version 2.2.3-alt2. \nSecurity Fix(es):\n\n * #37701: Нет файлов локализации.\n\n * #49294: нет русской локализации в интерфейсе uget", + "Advisory": { + "From": "errata.altlinux.org", + "Severity": "Low", + "Rights": "Copyright 2024 BaseALT Ltd.", + "Issued": { + "Date": "2024-03-24" + }, + "Updated": { + "Date": "2024-03-24" + }, + "bdu": null, + "Bugzilla": [ + { + "Id": "37701", + "Href": "https://bugzilla.altlinux.org/37701", + "Data": "Нет файлов локализации." + }, + { + "Id": "49294", + "Href": "https://bugzilla.altlinux.org/49294", + "Data": "нет русской локализации в интерфейсе uget" + } + ], + "AffectedCpeList": { + "Cpe": [ + "cpe:/o:alt:kworkstation:10", + "cpe:/o:alt:workstation:10", + "cpe:/o:alt:server:10", + "cpe:/o:alt:server-v:10", + "cpe:/o:alt:education:10", + "cpe:/o:alt:slinux:10", + "cpe:/o:alt:starterkit:p10", + "cpe:/o:alt:kworkstation:10.1", + "cpe:/o:alt:workstation:10.1", + "cpe:/o:alt:server:10.1", + "cpe:/o:alt:server-v:10.1", + "cpe:/o:alt:education:10.1", + "cpe:/o:alt:slinux:10.1", + "cpe:/o:alt:starterkit:10.1", + "cpe:/o:alt:kworkstation:10.2", + "cpe:/o:alt:workstation:10.2", + "cpe:/o:alt:server:10.2", + "cpe:/o:alt:server-v:10.2", + "cpe:/o:alt:education:10.2", + "cpe:/o:alt:slinux:10.2", + "cpe:/o:alt:starterkit:10.2" + ] + } + } + }, + "Criteria": { + "Operator": "AND", + "Criterions": [ + { + "TestRef": "oval:org.altlinux.errata:tst:2001", + "Comment": "ALT Linux must be installed" + } + ], + "Criterias": [ + { + "Operator": "OR", + "Criterions": [ + { + "TestRef": "oval:org.altlinux.errata:tst:20244151001", + "Comment": "uget is earlier than 0:2.2.3-alt2" + } + ] + } + ] + } + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-4151/objects.json b/oval/p10/ALT-PU-2024-4151/objects.json new file mode 100644 index 0000000000..9870ecdcfc --- /dev/null +++ b/oval/p10/ALT-PU-2024-4151/objects.json @@ -0,0 +1,34 @@ +{ + "TextFileContent54Objects": [ + { + "ID": "oval:org.altlinux.errata:obj:2001", + "Version": "1", + "comment": "Evaluate `/etc/os-release` file content", + "Path": { + "dataType": "string", + "Text": "/etc" + }, + "Filepath": { + "Datatype": "string", + "Text": "os-release" + }, + "Pattern": { + "Datatype": "string", + "Operation": "pattern match", + "Text": "cpe:\\/o:alt:(?!sp)[a-z\\-]+:p?(\\d+)(?:\\.\\d)*" + }, + "Instance": { + "Datatype": "int", + "Text": "1" + } + } + ], + "RpmInfoObjects": [ + { + "ID": "oval:org.altlinux.errata:obj:20244151001", + "Version": "1", + "comment": "uget is installed", + "Name": "uget" + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-4151/states.json b/oval/p10/ALT-PU-2024-4151/states.json new file mode 100644 index 0000000000..2284cf4c3a --- /dev/null +++ b/oval/p10/ALT-PU-2024-4151/states.json @@ -0,0 +1,23 @@ +{ + "TextFileContent54State": [ + { + "ID": "oval:org.altlinux.errata:ste:2001", + "Version": "1", + "Text": {} + } + ], + "RpmInfoState": [ + { + "ID": "oval:org.altlinux.errata:ste:20244151001", + "Version": "1", + "Comment": "package EVR is earlier than 0:2.2.3-alt2", + "Arch": {}, + "Evr": { + "Text": "0:2.2.3-alt2", + "Datatype": "evr_string", + "Operation": "less than" + }, + "Subexpression": {} + } + ] +} \ No newline at end of file diff --git a/oval/p10/ALT-PU-2024-4151/tests.json b/oval/p10/ALT-PU-2024-4151/tests.json new file mode 100644 index 0000000000..2d6900f3e2 --- /dev/null +++ b/oval/p10/ALT-PU-2024-4151/tests.json @@ -0,0 +1,30 @@ +{ + "TextFileContent54Tests": [ + { + "ID": "oval:org.altlinux.errata:tst:2001", + "Version": "1", + "Check": "all", + "Comment": "ALT Linux based on branch 'p10' must be installed", + "Object": { + "ObjectRef": "oval:org.altlinux.errata:obj:2001" + }, + "State": { + "StateRef": "oval:org.altlinux.errata:ste:2001" + } + } + ], + "RPMInfoTests": [ + { + "ID": "oval:org.altlinux.errata:tst:20244151001", + "Version": "1", + "Check": "all", + "Comment": "uget is earlier than 0:2.2.3-alt2", + "Object": { + "ObjectRef": "oval:org.altlinux.errata:obj:20244151001" + }, + "State": { + "StateRef": "oval:org.altlinux.errata:ste:20244151001" + } + } + ] +} \ No newline at end of file