vuln-list-alt/oval/c9f2/ALT-PU-2024-7581/definitions.json
2024-12-12 21:07:30 +00:00

168 lines
6.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20247581",
"Version": "oval:org.altlinux.errata:def:20247581",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-7581: package `git` update to version 2.42.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-7581",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-7581",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-01718",
"RefURL": "https://bdu.fstec.ru/vul/2023-01718",
"Source": "BDU"
},
{
"RefID": "CVE-2022-24975",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-24975",
"Source": "CVE"
}
],
"Description": "This update upgrades git to version 2.42.1-alt1. \nSecurity Fix(es):\n\n * BDU:2023-01718: Уязвимость распределенной системы управления версиями Git, связанная с раскрытием информации в ошибочной области данных, позволяющая нарушителю получить доступ к конфиденциальным данным\n\n * CVE-2022-24975: The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the \"GitBleed\" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.\n\n * #47999: git version update",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-05-11"
},
"Updated": {
"Date": "2024-05-11"
},
"BDUs": [
{
"ID": "BDU:2023-01718",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-668",
"Href": "https://bdu.fstec.ru/vul/2023-01718",
"Impact": "Low",
"Public": "20220211"
}
],
"CVEs": [
{
"ID": "CVE-2022-24975",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-668",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-24975",
"Impact": "High",
"Public": "20220211"
}
],
"Bugzilla": [
{
"ID": "47999",
"Href": "https://bugzilla.altlinux.org/47999",
"Data": "git version update"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20247581001",
"Comment": "git is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581002",
"Comment": "git-arch is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581003",
"Comment": "git-contrib is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581004",
"Comment": "git-core is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581005",
"Comment": "git-cvs is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581006",
"Comment": "git-diff-highlight is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581007",
"Comment": "git-doc is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581008",
"Comment": "git-email is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581009",
"Comment": "git-full is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581010",
"Comment": "git-gui is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581011",
"Comment": "git-server is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581012",
"Comment": "git-subtree is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581013",
"Comment": "git-svn is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581014",
"Comment": "gitk is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581015",
"Comment": "gitweb is earlier than 0:2.42.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20247581016",
"Comment": "perl-Git is earlier than 0:2.42.1-alt1"
}
]
}
]
}
}
]
}