vuln-list-alt/oval/c10f1/ALT-PU-2019-3403/definitions.json
2024-12-12 21:07:30 +00:00

113 lines
4.1 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20193403",
"Version": "oval:org.altlinux.errata:def:20193403",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-3403: package `dpdk` update to version 18.11.5-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-3403",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-3403",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01861",
"RefURL": "https://bdu.fstec.ru/vul/2020-01861",
"Source": "BDU"
},
{
"RefID": "CVE-2019-14818",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-14818",
"Source": "CVE"
}
],
"Description": "This update upgrades dpdk to version 18.11.5-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01861: Уязвимость набора библиотек и драйверов для быстрой обработки пакетов dpdk, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-14818: A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-12-27"
},
"Updated": {
"Date": "2019-12-27"
},
"BDUs": [
{
"ID": "BDU:2020-01861",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400, CWE-772",
"Href": "https://bdu.fstec.ru/vul/2020-01861",
"Impact": "High",
"Public": "20191112"
}
],
"CVEs": [
{
"ID": "CVE-2019-14818",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-401",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-14818",
"Impact": "High",
"Public": "20191114"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:5001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20193403001",
"Comment": "dpdk is earlier than 0:18.11.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193403002",
"Comment": "dpdk-devel is earlier than 0:18.11.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193403003",
"Comment": "dpdk-examples is earlier than 0:18.11.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193403004",
"Comment": "dpdk-tools is earlier than 0:18.11.5-alt1"
}
]
}
]
}
}
]
}