2024-07-06 03:04:52 +00:00

120 lines
4.4 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20192569",
"Version": "oval:org.altlinux.errata:def:20192569",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-2569: package `libsmi` update to version 0.5.0-alt1.svn1841",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-2569",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-2569",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-03137",
"RefURL": "https://bdu.fstec.ru/vul/2015-03137",
"Source": "BDU"
},
{
"RefID": "BDU:2015-09693",
"RefURL": "https://bdu.fstec.ru/vul/2015-09693",
"Source": "BDU"
},
{
"RefID": "CVE-2010-2891",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2010-2891",
"Source": "CVE"
}
],
"Description": "This update upgrades libsmi to version 0.5.0-alt1.svn1841. \nSecurity Fix(es):\n\n * BDU:2015-03137: Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации\n\n * BDU:2015-09693: Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации\n\n * CVE-2010-2891: Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-08-29"
},
"Updated": {
"Date": "2019-08-29"
},
"BDUs": [
{
"ID": "BDU:2015-03137",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-03137",
"Impact": "High",
"Public": "20101028"
},
{
"ID": "BDU:2015-09693",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2015-09693",
"Impact": "High",
"Public": "20131214"
}
],
"CVEs": [
{
"ID": "CVE-2010-2891",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2010-2891",
"Impact": "High",
"Public": "20101028"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20192569001",
"Comment": "libsmi is earlier than 0:0.5.0-alt1.svn1841"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192569002",
"Comment": "libsmi-devel is earlier than 0:0.5.0-alt1.svn1841"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192569003",
"Comment": "smi-tools is earlier than 0:0.5.0-alt1.svn1841"
}
]
}
]
}
}
]
}