vuln-list-alt/oval/c10f1/ALT-PU-2017-2477/definitions.json
2024-06-28 13:17:52 +00:00

230 lines
9.8 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172477",
"Version": "oval:org.altlinux.errata:def:20172477",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2477: package `apache2` update to version 2.4.28-alt1.S1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2477",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2477",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-00103",
"RefURL": "https://bdu.fstec.ru/vul/2018-00103",
"Source": "BDU"
},
{
"RefID": "CVE-2017-9798",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-9798",
"Source": "CVE"
}
],
"Description": "This update upgrades apache2 to version 2.4.28-alt1.S1. \nSecurity Fix(es):\n\n * BDU:2018-00103: Уязвимость функции ap_limit_section httpd-демона веб-сервера Apache HTTP Server, позволяющая нарушителю получить доступ к данным из памяти процесса\n\n * CVE-2017-9798: Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2.2.34 and 2.4.x through 2.4.27. The attacker sends an unauthenticated OPTIONS HTTP request when attempting to read secret data. This is a use-after-free issue and thus secret data is not always sent, and the specific data depends on many factors including configuration. Exploitation with .htaccess can be blocked with a patch to the ap_limit_section function in server/core.c.\n\n * #31062: нестабильно работает service httpd2 restart\n\n * #32269: AH00548: NameVirtualHost has no effect and will be removed in the next release /etc/httpd2/conf/sites-enabled/ports_all.conf:9\n\n * #33978: автоматически не стартует при холодном старте системы",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-10-20"
},
"Updated": {
"Date": "2017-10-20"
},
"BDUs": [
{
"ID": "BDU:2018-00103",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2018-00103",
"Impact": "Low",
"Public": "20170918"
}
],
"CVEs": [
{
"ID": "CVE-2017-9798",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-9798",
"Impact": "High",
"Public": "20170918"
}
],
"Bugzilla": [
{
"ID": "31062",
"Href": "https://bugzilla.altlinux.org/31062",
"Data": "нестабильно работает service httpd2 restart"
},
{
"ID": "32269",
"Href": "https://bugzilla.altlinux.org/32269",
"Data": "AH00548: NameVirtualHost has no effect and will be removed in the next release /etc/httpd2/conf/sites-enabled/ports_all.conf:9"
},
{
"ID": "33978",
"Href": "https://bugzilla.altlinux.org/33978",
"Data": "автоматически не стартует при холодном старте системы"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172477001",
"Comment": "apache2 is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477002",
"Comment": "apache2-ab is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477003",
"Comment": "apache2-base is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477004",
"Comment": "apache2-cgi-bin is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477005",
"Comment": "apache2-cgi-bin-printenv is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477006",
"Comment": "apache2-cgi-bin-test-cgi is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477007",
"Comment": "apache2-compat is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477008",
"Comment": "apache2-configs-A1PROXIED is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477009",
"Comment": "apache2-datadirs is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477010",
"Comment": "apache2-devel is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477011",
"Comment": "apache2-docs is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477012",
"Comment": "apache2-full is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477013",
"Comment": "apache2-htcacheclean is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477014",
"Comment": "apache2-htcacheclean-control is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477015",
"Comment": "apache2-html is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477016",
"Comment": "apache2-htpasswd is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477017",
"Comment": "apache2-httpd-event is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477018",
"Comment": "apache2-httpd-prefork is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477019",
"Comment": "apache2-httpd-worker is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477020",
"Comment": "apache2-icons is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477021",
"Comment": "apache2-manual is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477022",
"Comment": "apache2-manual-addons is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477023",
"Comment": "apache2-mod_cache_disk is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477024",
"Comment": "apache2-mod_ldap is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477025",
"Comment": "apache2-mod_ssl is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477026",
"Comment": "apache2-mod_ssl-compat is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477027",
"Comment": "apache2-mods is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477028",
"Comment": "apache2-suexec is earlier than 1:2.4.28-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172477029",
"Comment": "rpm-build-apache2 is earlier than 1:2.4.28-alt1.S1"
}
]
}
]
}
}
]
}