vuln-list-alt/oval/c9f2/ALT-PU-2018-2222/definitions.json
2024-06-28 13:17:52 +00:00

125 lines
4.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20182222",
"Version": "oval:org.altlinux.errata:def:20182222",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-2222: package `openssh` update to version 7.2p2-alt3",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-2222",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-2222",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-01037",
"RefURL": "https://bdu.fstec.ru/vul/2018-01037",
"Source": "BDU"
},
{
"RefID": "CVE-2018-15473",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15473",
"Source": "CVE"
}
],
"Description": "This update upgrades openssh to version 7.2p2-alt3. \nSecurity Fix(es):\n\n * BDU:2018-01037: Уязвимость средства криптографической защиты OpenSSH, связанная с различной реакцией сервера на запросы аутентификации, позволяющая нарушителю выявить существующие учетные записи пользователей\n\n * CVE-2018-15473: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-08-24"
},
"Updated": {
"Date": "2018-08-24"
},
"BDUs": [
{
"ID": "BDU:2018-01037",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2018-01037",
"Impact": "High",
"Public": "20180817"
}
],
"CVEs": [
{
"ID": "CVE-2018-15473",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-362",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15473",
"Impact": "Low",
"Public": "20180817"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20182222001",
"Comment": "openssh is earlier than 0:7.2p2-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182222002",
"Comment": "openssh-askpass-common is earlier than 0:7.2p2-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182222003",
"Comment": "openssh-clients is earlier than 0:7.2p2-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182222004",
"Comment": "openssh-common is earlier than 0:7.2p2-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182222005",
"Comment": "openssh-keysign is earlier than 0:7.2p2-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182222006",
"Comment": "openssh-server is earlier than 0:7.2p2-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182222007",
"Comment": "openssh-server-control is earlier than 0:7.2p2-alt3"
}
]
}
]
}
}
]
}