vuln-list-alt/oval/c10f1/ALT-PU-2017-3593/definitions.json
2024-06-28 13:17:52 +00:00

100 lines
3.4 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20173593",
"Version": "oval:org.altlinux.errata:def:20173593",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-3593: package `supervisor` update to version 3.3.3-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-3593",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-3593",
"Source": "ALTPU"
},
{
"RefID": "BDU:2017-02043",
"RefURL": "https://bdu.fstec.ru/vul/2017-02043",
"Source": "BDU"
},
{
"RefID": "CVE-2017-11610",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-11610",
"Source": "CVE"
}
],
"Description": "This update upgrades supervisor to version 3.3.3-alt1. \nSecurity Fix(es):\n\n * BDU:2017-02043: Уязвимость компонента XML-RPC веб-сервера Supervisor и операционных систем Fedora, Debian GNU/Linux , позволяющая нарушителю выполнить произвольные команды\n\n * CVE-2017-11610: The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-04-08"
},
"Updated": {
"Date": "2024-04-08"
},
"BDUs": [
{
"ID": "BDU:2017-02043",
"CVSS": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"CWE": "CWE-284",
"Href": "https://bdu.fstec.ru/vul/2017-02043",
"Impact": "Critical",
"Public": "20170807"
}
],
"CVEs": [
{
"ID": "CVE-2017-11610",
"CVSS": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-276",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-11610",
"Impact": "High",
"Public": "20170823"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20173593001",
"Comment": "supervisor is earlier than 0:3.3.3-alt1"
}
]
}
]
}
}
]
}