vuln-list-alt/oval/c9f2/ALT-PU-2019-2662/definitions.json
2024-06-28 13:17:52 +00:00

575 lines
30 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20192662",
"Version": "oval:org.altlinux.errata:def:20192662",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-2662: package `libvncserver` update to version 0.9.12-alt2",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-2662",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-2662",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-01493",
"RefURL": "https://bdu.fstec.ru/vul/2018-01493",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00694",
"RefURL": "https://bdu.fstec.ru/vul/2019-00694",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00695",
"RefURL": "https://bdu.fstec.ru/vul/2019-00695",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00696",
"RefURL": "https://bdu.fstec.ru/vul/2019-00696",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00697",
"RefURL": "https://bdu.fstec.ru/vul/2019-00697",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00698",
"RefURL": "https://bdu.fstec.ru/vul/2019-00698",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00699",
"RefURL": "https://bdu.fstec.ru/vul/2019-00699",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00700",
"RefURL": "https://bdu.fstec.ru/vul/2019-00700",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00701",
"RefURL": "https://bdu.fstec.ru/vul/2019-00701",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00702",
"RefURL": "https://bdu.fstec.ru/vul/2019-00702",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00703",
"RefURL": "https://bdu.fstec.ru/vul/2019-00703",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00704",
"RefURL": "https://bdu.fstec.ru/vul/2019-00704",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00705",
"RefURL": "https://bdu.fstec.ru/vul/2019-00705",
"Source": "BDU"
},
{
"RefID": "BDU:2020-02922",
"RefURL": "https://bdu.fstec.ru/vul/2020-02922",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03149",
"RefURL": "https://bdu.fstec.ru/vul/2020-03149",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03151",
"RefURL": "https://bdu.fstec.ru/vul/2020-03151",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03957",
"RefURL": "https://bdu.fstec.ru/vul/2020-03957",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03959",
"RefURL": "https://bdu.fstec.ru/vul/2020-03959",
"Source": "BDU"
},
{
"RefID": "CVE-2017-18922",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-18922",
"Source": "CVE"
},
{
"RefID": "CVE-2018-15126",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15126",
"Source": "CVE"
},
{
"RefID": "CVE-2018-15127",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15127",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20019",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20019",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20020",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20020",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20021",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20021",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20022",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20022",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20023",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20023",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20024",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20024",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20748",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20748",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20749",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20749",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20750",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20750",
"Source": "CVE"
},
{
"RefID": "CVE-2018-6307",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-6307",
"Source": "CVE"
},
{
"RefID": "CVE-2018-7225",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-7225",
"Source": "CVE"
},
{
"RefID": "CVE-2019-15681",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-15681",
"Source": "CVE"
},
{
"RefID": "CVE-2020-14404",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-14404",
"Source": "CVE"
},
{
"RefID": "CVE-2020-14405",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-14405",
"Source": "CVE"
}
],
"Description": "This update upgrades libvncserver to version 0.9.12-alt2. \nSecurity Fix(es):\n\n * BDU:2018-01493: Уязвимость функции rfbProcessClientNormalMessage() кроссплатформенной библиотеки LibVNCServer, позволяющая нарушителю вызвать отказ в обслуживании и получить несанкционированный доступ к конфиденциальным данным\n\n * BDU:2019-00694: Уязвимость библиотеки LibVNC, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2019-00695: Уязвимость библиотеки LibVNC, связанная со считыванием данных за пределами заданного буфера, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2019-00696: Уязвимость библиотеки LibVNC, связанная со считыванием данных за пределами заданного буфера, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2019-00697: Уязвимость библиотеки LibVNC, связанная со считыванием данных за пределами заданного буфера, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2019-00698: Уязвимость библиотеки LibVNC, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2019-00699: Уязвимость библиотеки LibVNC, связанная с ошибками инициализации в коде клиента, позволяющая нарушителю раскрыть защищаемую информацию\n\n * BDU:2019-00700: Уязвимость компонента VNC Repeater библиотеки LibVNC, позволяющая нарушителю раскрыть защищаемую информацию\n\n * BDU:2019-00701: Уязвимость библиотеки LibVNC, связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2019-00702: Уязвимость компонента rfbproto.c кроссплатформенной библиотеки LibVNCServer, связанная с записью за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании и получить несанкционированный доступ к конфиденциальным данным\n\n * BDU:2019-00703: Уязвимость компонента rfbserver.c кроссплатформенной библиотеки LibVNCServer, связанная с записью за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании и получить несанкционированный доступ к конфиденциальным данным\n\n * BDU:2019-00704: Уязвимость компонента rfbserver.c кроссплатформенной библиотеки LibVNCServer, связанная с записью за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании и получить несанкционированный доступ к конфиденциальным данным\n\n * BDU:2019-00705: Уязвимость библиотеки LibVNC, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2020-02922: Уязвимость кроссплатформенной библиотеки LibVNCServer, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю получить несанкционированный доступ к информации\n\n * BDU:2020-03149: Уязвимость компонента libvncclient/rfbproto.c кроссплатформенной библиотеки LibVNCServer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации\n\n * BDU:2020-03151: Уязвимость компонента libvncserver/rre.c кроссплатформенной библиотеки LibVNCServer, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации\n\n * BDU:2020-03957: Уязвимость компонента websockets.c кроссплатформенной библиотеки LibVNCServer, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-03959: Уязвимость компонента libvncclient/sockets.c кроссплатформенной библиотеки LibVNCServer, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * CVE-2017-18922: It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.\n\n * CVE-2018-15126: LibVNC before commit 73cb96fec028a576a5a24417b57723b55854ad7b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution\n\n * CVE-2018-15127: LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution\n\n * CVE-2018-20019: LibVNC before commit a83439b9fbe0f03c48eb94ed05729cb016f8b72f contains multiple heap out-of-bound write vulnerabilities in VNC client code that can result remote code execution\n\n * CVE-2018-20020: LibVNC before commit 7b1ef0ffc4815cab9a96c7278394152bdc89dc4d contains heap out-of-bound write vulnerability inside structure in VNC client code that can result remote code execution\n\n * CVE-2018-20021: LibVNC before commit c3115350eb8bb635d0fdb4dbbb0d0541f38ed19c contains a CWE-835: Infinite loop vulnerability in VNC client code. Vulnerability allows attacker to consume excessive amount of resources like CPU and RAM\n\n * CVE-2018-20022: LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR\n\n * CVE-2018-20023: LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allows attacker to read stack memory and can be abuse for information disclosure. Combined with another vulnerability, it can be used to leak stack memory layout and in bypassing ASLR\n\n * CVE-2018-20024: LibVNC before commit 4a21bbd097ef7c44bb000c3bd0907f96a10e4ce7 contains null pointer dereference in VNC client code that can result DoS.\n\n * CVE-2018-20748: LibVNC before 0.9.12 contains multiple heap out-of-bounds write vulnerabilities in libvncclient/rfbproto.c. The fix for CVE-2018-20019 was incomplete.\n\n * CVE-2018-20749: LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.\n\n * CVE-2018-20750: LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.\n\n * CVE-2018-6307: LibVNC before commit ca2a5ac02fbbadd0a21fabba779c1ea69173d10b contains heap use-after-free vulnerability in server code of file transfer extension that can result remote code execution.\n\n * CVE-2018-7225: An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to access to uninitialized and potentially sensitive data or possibly unspecified other impact (e.g., an integer overflow) via specially crafted VNC packets.\n\n * CVE-2019-15681: LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a.\n\n * CVE-2020-14404: An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.\n\n * CVE-2020-14405: An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-09-09"
},
"Updated": {
"Date": "2019-09-09"
},
"BDUs": [
{
"ID": "BDU:2018-01493",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-190",
"Href": "https://bdu.fstec.ru/vul/2018-01493",
"Impact": "Critical",
"Public": "20180218"
},
{
"ID": "BDU:2019-00694",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2019-00694",
"Impact": "Critical",
"Public": "20180814"
},
{
"ID": "BDU:2019-00695",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2019-00695",
"Impact": "Critical",
"Public": "20180814"
},
{
"ID": "BDU:2019-00696",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2019-00696",
"Impact": "Critical",
"Public": "20180814"
},
{
"ID": "BDU:2019-00697",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2019-00697",
"Impact": "Critical",
"Public": "20180814"
},
{
"ID": "BDU:2019-00698",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://bdu.fstec.ru/vul/2019-00698",
"Impact": "High",
"Public": "20180911"
},
{
"ID": "BDU:2019-00699",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"CWE": "CWE-200, CWE-665",
"Href": "https://bdu.fstec.ru/vul/2019-00699",
"Impact": "High",
"Public": "20180911"
},
{
"ID": "BDU:2019-00700",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"CWE": "CWE-200, CWE-665",
"Href": "https://bdu.fstec.ru/vul/2019-00700",
"Impact": "High",
"Public": "20180911"
},
{
"ID": "BDU:2019-00701",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2019-00701",
"Impact": "High",
"Public": "20180911"
},
{
"ID": "BDU:2019-00702",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2019-00702",
"Impact": "Critical",
"Public": "20181229"
},
{
"ID": "BDU:2019-00703",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2019-00703",
"Impact": "Critical",
"Public": "20190106"
},
{
"ID": "BDU:2019-00704",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2019-00704",
"Impact": "Critical",
"Public": "20190107"
},
{
"ID": "BDU:2019-00705",
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-434",
"Href": "https://bdu.fstec.ru/vul/2019-00705",
"Impact": "High",
"Public": "20180814"
},
{
"ID": "BDU:2020-02922",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-665, CWE-772",
"Href": "https://bdu.fstec.ru/vul/2020-02922",
"Impact": "High",
"Public": "20191029"
},
{
"ID": "BDU:2020-03149",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-770",
"Href": "https://bdu.fstec.ru/vul/2020-03149",
"Impact": "Low",
"Public": "20200617"
},
{
"ID": "BDU:2020-03151",
"CVSS": "AV:N/AC:L/Au:S/C:P/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2020-03151",
"Impact": "Low",
"Public": "20200617"
},
{
"ID": "BDU:2020-03957",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2020-03957",
"Impact": "Critical",
"Public": "20170514"
},
{
"ID": "BDU:2020-03959",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-120",
"Href": "https://bdu.fstec.ru/vul/2020-03959",
"Impact": "High",
"Public": "20190406"
}
],
"CVEs": [
{
"ID": "CVE-2017-18922",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-18922",
"Impact": "Critical",
"Public": "20200630"
},
{
"ID": "CVE-2018-15126",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15126",
"Impact": "Critical",
"Public": "20181219"
},
{
"ID": "CVE-2018-15127",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15127",
"Impact": "Critical",
"Public": "20181219"
},
{
"ID": "CVE-2018-20019",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20019",
"Impact": "Critical",
"Public": "20181219"
},
{
"ID": "CVE-2018-20020",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20020",
"Impact": "Critical",
"Public": "20181219"
},
{
"ID": "CVE-2018-20021",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20021",
"Impact": "High",
"Public": "20181219"
},
{
"ID": "CVE-2018-20022",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-665",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20022",
"Impact": "High",
"Public": "20181219"
},
{
"ID": "CVE-2018-20023",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-665",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20023",
"Impact": "High",
"Public": "20181219"
},
{
"ID": "CVE-2018-20024",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20024",
"Impact": "High",
"Public": "20181219"
},
{
"ID": "CVE-2018-20748",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20748",
"Impact": "Critical",
"Public": "20190130"
},
{
"ID": "CVE-2018-20749",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20749",
"Impact": "Critical",
"Public": "20190130"
},
{
"ID": "CVE-2018-20750",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20750",
"Impact": "Critical",
"Public": "20190130"
},
{
"ID": "CVE-2018-6307",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-6307",
"Impact": "High",
"Public": "20181219"
},
{
"ID": "CVE-2018-7225",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-190",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-7225",
"Impact": "Critical",
"Public": "20180219"
},
{
"ID": "CVE-2019-15681",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-665",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-15681",
"Impact": "High",
"Public": "20191029"
},
{
"ID": "CVE-2020-14404",
"CVSS": "AV:N/AC:L/Au:S/C:P/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-14404",
"Impact": "Low",
"Public": "20200617"
},
{
"ID": "CVE-2020-14405",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-770",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-14405",
"Impact": "Low",
"Public": "20200617"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20192662001",
"Comment": "libvncclient0 is earlier than 0:0.9.12-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192662002",
"Comment": "libvncserver is earlier than 0:0.9.12-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192662003",
"Comment": "libvncserver-devel is earlier than 0:0.9.12-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192662004",
"Comment": "libvncserver0 is earlier than 0:0.9.12-alt2"
}
]
}
]
}
}
]
}