vuln-list-alt/oval/c10f1/ALT-PU-2020-1282/definitions.json
2024-12-12 21:07:30 +00:00

139 lines
5.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20201282",
"Version": "oval:org.altlinux.errata:def:20201282",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-1282: package `qt5-quickcontrols2` update to version 5.12.7-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-1282",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1282",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-01758",
"RefURL": "https://bdu.fstec.ru/vul/2022-01758",
"Source": "BDU"
},
{
"RefID": "CVE-2020-0570",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-0570",
"Source": "CVE"
},
{
"RefID": "CVE-2020-24742",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-24742",
"Source": "CVE"
}
],
"Description": "This update upgrades qt5-quickcontrols2 to version 5.12.7-alt1. \nSecurity Fix(es):\n\n * BDU:2022-01758: Уязвимость компонента QPluginLoader кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2020-0570: Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.\n\n * CVE-2020-24742: An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-02-19"
},
"Updated": {
"Date": "2020-02-19"
},
"BDUs": [
{
"ID": "BDU:2022-01758",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2022-01758",
"Impact": "High",
"Public": "20210809"
}
],
"CVEs": [
{
"ID": "CVE-2020-0570",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-426",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-0570",
"Impact": "High",
"Public": "20200914"
},
{
"ID": "CVE-2020-24742",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-24742",
"Impact": "High",
"Public": "20210809"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:5001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20201282001",
"Comment": "libqt5-quickcontrols2 is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201282002",
"Comment": "libqt5-quicktemplates2 is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201282003",
"Comment": "qt5-quickcontrols2 is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201282004",
"Comment": "qt5-quickcontrols2-common is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201282005",
"Comment": "qt5-quickcontrols2-devel is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201282006",
"Comment": "qt5-quickcontrols2-devel-static is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201282007",
"Comment": "qt5-quickcontrols2-doc is earlier than 0:5.12.7-alt1"
}
]
}
]
}
}
]
}