2024-12-12 21:07:30 +00:00

161 lines
6.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20181863",
"Version": "oval:org.altlinux.errata:def:20181863",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-1863: package `libvorbis` update to version 1.3.6-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-1863",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-1863",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-05863",
"RefURL": "https://bdu.fstec.ru/vul/2022-05863",
"Source": "BDU"
},
{
"RefID": "CVE-2017-11333",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-11333",
"Source": "CVE"
},
{
"RefID": "CVE-2017-14160",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-14160",
"Source": "CVE"
},
{
"RefID": "CVE-2017-14632",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-14632",
"Source": "CVE"
},
{
"RefID": "CVE-2017-14633",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-14633",
"Source": "CVE"
},
{
"RefID": "CVE-2020-20412",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-20412",
"Source": "CVE"
}
],
"Description": "This update upgrades libvorbis to version 1.3.6-alt1. \nSecurity Fix(es):\n\n * BDU:2022-05863: Уязвимость функции bark_noise_hybridmp компонента psy.c мультимедийной библиотеки Vorbis, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2017-11333: The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.\n\n * CVE-2017-14160: The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.\n\n * CVE-2017-14632: Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi-\u003echannels\u003c=0, a similar issue to Mozilla bug 550184.\n\n * CVE-2017-14633: In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().\n\n * CVE-2020-20412: lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-06-06"
},
"Updated": {
"Date": "2018-06-06"
},
"BDUs": [
{
"ID": "BDU:2022-05863",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2022-05863",
"Impact": "High",
"Public": "20170921"
}
],
"CVEs": [
{
"ID": "CVE-2017-11333",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-11333",
"Impact": "Low",
"Public": "20170731"
},
{
"ID": "CVE-2017-14160",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-14160",
"Impact": "High",
"Public": "20170921"
},
{
"ID": "CVE-2017-14632",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-14632",
"Impact": "Critical",
"Public": "20170921"
},
{
"ID": "CVE-2017-14633",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-14633",
"Impact": "Low",
"Public": "20170921"
},
{
"ID": "CVE-2020-20412",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-129",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-20412",
"Impact": "Low",
"Public": "20201226"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:5001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20181863001",
"Comment": "libvorbis is earlier than 0:1.3.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181863002",
"Comment": "libvorbis-devel is earlier than 0:1.3.6-alt1"
}
]
}
]
}
}
]
}