{ "Definition": [ { "ID": "oval:org.altlinux.errata:def:20182584", "Version": "oval:org.altlinux.errata:def:20182584", "Class": "patch", "Metadata": { "Title": "ALT-PU-2018-2584: package `NetworkManager` update to version 1.14.5-alt1.gitba83251bba87", "AffectedList": [ { "Family": "unix", "Platforms": [ "ALT Linux branch c9f2" ], "Products": [ "ALT SPWorkstation", "ALT SPServer" ] } ], "References": [ { "RefID": "ALT-PU-2018-2584", "RefURL": "https://errata.altlinux.org/ALT-PU-2018-2584", "Source": "ALTPU" }, { "RefID": "BDU:2018-01289", "RefURL": "https://bdu.fstec.ru/vul/2018-01289", "Source": "BDU" }, { "RefID": "CVE-2018-15688", "RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15688", "Source": "CVE" } ], "Description": "This update upgrades NetworkManager to version 1.14.5-alt1.gitba83251bba87. \nSecurity Fix(es):\n\n * BDU:2018-01289: Уязвимость функции dhcp6_option_append_ia() демона Systemd, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * CVE-2018-15688: A buffer overflow vulnerability in the dhcp6 client of systemd allows a malicious dhcp6 server to overwrite heap memory in systemd-networkd. Affected releases are systemd: versions up to and including 239.", "Advisory": { "From": "errata.altlinux.org", "Severity": "High", "Rights": "Copyright 2024 BaseALT Ltd.", "Issued": { "Date": "2018-11-01" }, "Updated": { "Date": "2018-11-01" }, "BDUs": [ { "ID": "BDU:2018-01289", "CVSS": "AV:A/AC:L/Au:N/C:C/I:C/A:C", "CVSS3": "AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "CWE": "CWE-122, CWE-131, CWE-190", "Href": "https://bdu.fstec.ru/vul/2018-01289", "Impact": "High", "Public": "20181014" } ], "CVEs": [ { "ID": "CVE-2018-15688", "CVSS": "AV:A/AC:L/Au:N/C:P/I:P/A:P", "CVSS3": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "CWE": "CWE-120", "Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15688", "Impact": "High", "Public": "20181026" } ], "AffectedCPEs": { "CPEs": [ "cpe:/o:alt:spworkstation:8.4", "cpe:/o:alt:spserver:8.4" ] } } }, "Criteria": { "Operator": "AND", "Criterions": [ { "TestRef": "oval:org.altlinux.errata:tst:4001", "Comment": "ALT Linux must be installed" } ], "Criterias": [ { "Operator": "OR", "Criterions": [ { "TestRef": "oval:org.altlinux.errata:tst:20182584001", "Comment": "NetworkManager is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584002", "Comment": "NetworkManager-adsl is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584003", "Comment": "NetworkManager-bluetooth is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584004", "Comment": "NetworkManager-daemon is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584005", "Comment": "NetworkManager-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584006", "Comment": "NetworkManager-devel-doc is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584007", "Comment": "NetworkManager-glib-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584008", "Comment": "NetworkManager-glib-gir is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584009", "Comment": "NetworkManager-glib-gir-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584010", "Comment": "NetworkManager-ovs is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584011", "Comment": "NetworkManager-ppp is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584012", "Comment": "NetworkManager-team is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584013", "Comment": "NetworkManager-tui is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584014", "Comment": "NetworkManager-wifi is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584015", "Comment": "NetworkManager-wwan is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584016", "Comment": "libnm is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584017", "Comment": "libnm-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584018", "Comment": "libnm-devel-doc is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584019", "Comment": "libnm-gir is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584020", "Comment": "libnm-gir-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584021", "Comment": "libnm-glib-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584022", "Comment": "libnm-glib-vpn-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584023", "Comment": "libnm-glib-vpn1 is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584024", "Comment": "libnm-glib4 is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584025", "Comment": "libnm-util-devel is earlier than 0:1.14.5-alt1.gitba83251bba87" }, { "TestRef": "oval:org.altlinux.errata:tst:20182584026", "Comment": "libnm-util2 is earlier than 0:1.14.5-alt1.gitba83251bba87" } ] } ] } } ] }