2024-06-28 13:17:52 +00:00

129 lines
5.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20203226",
"Version": "oval:org.altlinux.errata:def:20203226",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-3226: package `python3-module-ecdsa` update to version 0.16.0-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-3226",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-3226",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01480",
"RefURL": "https://bdu.fstec.ru/vul/2020-01480",
"Source": "BDU"
},
{
"RefID": "BDU:2020-01481",
"RefURL": "https://bdu.fstec.ru/vul/2020-01481",
"Source": "BDU"
},
{
"RefID": "CVE-2019-14853",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-14853",
"Source": "CVE"
},
{
"RefID": "CVE-2019-14859",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-14859",
"Source": "CVE"
}
],
"Description": "This update upgrades python3-module-ecdsa to version 0.16.0-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01480: Уязвимость криптографической библиотеки Python ECDSA, связанная с недостаточной обработкой исключительных состояний, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-01481: Уязвимость криптографической библиотеки Python ECDSA, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации\n\n * CVE-2019-14853: An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.\n\n * CVE-2019-14859: A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-11-07"
},
"Updated": {
"Date": "2020-11-07"
},
"BDUs": [
{
"ID": "BDU:2020-01480",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-391, CWE-755",
"Href": "https://bdu.fstec.ru/vul/2020-01480",
"Impact": "High",
"Public": "20191007"
},
{
"ID": "BDU:2020-01481",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-347",
"Href": "https://bdu.fstec.ru/vul/2020-01481",
"Impact": "Critical",
"Public": "20191007"
}
],
"CVEs": [
{
"ID": "CVE-2019-14853",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-755",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-14853",
"Impact": "High",
"Public": "20191126"
},
{
"ID": "CVE-2019-14859",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-347",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-14859",
"Impact": "Critical",
"Public": "20200102"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20203226001",
"Comment": "python3-module-ecdsa is earlier than 0:0.16.0-alt1"
}
]
}
]
}
}
]
}