vuln-list-alt/oval/c10f1/ALT-PU-2021-2120/definitions.json
2024-12-12 21:07:30 +00:00

120 lines
4.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20212120",
"Version": "oval:org.altlinux.errata:def:20212120",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-2120: package `openvpn` update to version 2.5.3-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-2120",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2120",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-02221",
"RefURL": "https://bdu.fstec.ru/vul/2021-02221",
"Source": "BDU"
},
{
"RefID": "CVE-2020-15078",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-15078",
"Source": "CVE"
}
],
"Description": "This update upgrades openvpn to version 2.5.3-alt1. \nSecurity Fix(es):\n\n * BDU:2021-02221: Уязвимость функции отложенной аутентификации deferred_auth программного обеспечения OpenVPN, позволяющая нарушителю вынудить сервер вернуть сообщение PUSH_REPLY c данными о настройках VPN до отправки сообщения AUTH_FAILED\n\n * CVE-2020-15078: OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.\n\n * #39989: Миграция на /run и /run/lock",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-07-01"
},
"Updated": {
"Date": "2021-07-01"
},
"BDUs": [
{
"ID": "BDU:2021-02221",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-305",
"Href": "https://bdu.fstec.ru/vul/2021-02221",
"Impact": "Low",
"Public": "20210422"
}
],
"CVEs": [
{
"ID": "CVE-2020-15078",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-306",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-15078",
"Impact": "High",
"Public": "20210426"
}
],
"Bugzilla": [
{
"ID": "39989",
"Href": "https://bugzilla.altlinux.org/39989",
"Data": "Миграция на /run и /run/lock"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:5001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20212120001",
"Comment": "openvpn is earlier than 0:2.5.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212120002",
"Comment": "openvpn-devel is earlier than 0:2.5.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212120003",
"Comment": "openvpn-docs is earlier than 0:2.5.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212120004",
"Comment": "openvpn-plugins is earlier than 0:2.5.3-alt1"
}
]
}
]
}
}
]
}