2024-06-28 13:17:52 +00:00

157 lines
6.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20182232",
"Version": "oval:org.altlinux.errata:def:20182232",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-2232: package `openssl10` update to version 1.0.2p-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-2232",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-2232",
"Source": "ALTPU"
},
{
"RefID": "BDU:2019-00021",
"RefURL": "https://bdu.fstec.ru/vul/2019-00021",
"Source": "BDU"
},
{
"RefID": "BDU:2019-00186",
"RefURL": "https://bdu.fstec.ru/vul/2019-00186",
"Source": "BDU"
},
{
"RefID": "CVE-2018-0732",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-0732",
"Source": "CVE"
},
{
"RefID": "CVE-2018-0737",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-0737",
"Source": "CVE"
}
],
"Description": "This update upgrades openssl10 to version 1.0.2p-alt1. \nSecurity Fix(es):\n\n * BDU:2019-00021: Уязвимость алгоритма генерации RSA-ключа библиотеки OpenSSL, позволяющая нарушителю восстановить закрытый ключ\n\n * BDU:2019-00186: Уязвимость библиотеки OpenSSL, связанная с ошибками обработки криптографических ключей при использовании протокола DH (E), позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2018-0732: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).\n\n * CVE-2018-0737: The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-08-27"
},
"Updated": {
"Date": "2018-08-27"
},
"BDUs": [
{
"ID": "BDU:2019-00021",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-310",
"Href": "https://bdu.fstec.ru/vul/2019-00021",
"Impact": "Low",
"Public": "20180411"
},
{
"ID": "BDU:2019-00186",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-320, CWE-325",
"Href": "https://bdu.fstec.ru/vul/2019-00186",
"Impact": "High",
"Public": "20180612"
}
],
"CVEs": [
{
"ID": "CVE-2018-0732",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-320",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-0732",
"Impact": "High",
"Public": "20180612"
},
{
"ID": "CVE-2018-0737",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-327",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-0737",
"Impact": "Low",
"Public": "20180416"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20182232001",
"Comment": "libcrypto10 is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232002",
"Comment": "libssl-devel is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232003",
"Comment": "libssl-devel-static is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232004",
"Comment": "libssl10 is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232005",
"Comment": "openssl is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232006",
"Comment": "openssl-doc is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232007",
"Comment": "openssl-engines is earlier than 0:1.0.2p-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182232008",
"Comment": "tsget is earlier than 0:1.0.2p-alt1"
}
]
}
]
}
}
]
}