vuln-list-alt/oval/c10f1/ALT-PU-2019-1715/definitions.json
2024-12-12 21:07:30 +00:00

120 lines
4.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191715",
"Version": "oval:org.altlinux.errata:def:20191715",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1715: package `unixODBC` update to version 2.3.7-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1715",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1715",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-01498",
"RefURL": "https://bdu.fstec.ru/vul/2021-01498",
"Source": "BDU"
},
{
"RefID": "CVE-2018-7409",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-7409",
"Source": "CVE"
}
],
"Description": "This update upgrades unixODBC to version 2.3.7-alt1. \nSecurity Fix(es):\n\n * BDU:2021-01498: Уязвимость функции unicode_to_ansi_copy() файла DriverManager/__info.c библиотеки ODBC для UNIX UnixODBC, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2018-7409: In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.\n\n * #36597: Сломана сборка unixODBC",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-04-23"
},
"Updated": {
"Date": "2019-04-23"
},
"BDUs": [
{
"ID": "BDU:2021-01498",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2021-01498",
"Impact": "Critical",
"Public": "20180222"
}
],
"CVEs": [
{
"ID": "CVE-2018-7409",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-7409",
"Impact": "Critical",
"Public": "20180222"
}
],
"Bugzilla": [
{
"ID": "36597",
"Href": "https://bugzilla.altlinux.org/36597",
"Data": "Сломана сборка unixODBC"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:5001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191715001",
"Comment": "libunixODBC-devel is earlier than 0:2.3.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191715002",
"Comment": "libunixODBC-devel-compat is earlier than 0:2.3.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191715003",
"Comment": "libunixODBC2 is earlier than 0:2.3.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191715004",
"Comment": "unixODBC is earlier than 0:2.3.7-alt1"
}
]
}
]
}
}
]
}