2024-06-28 13:17:52 +00:00

242 lines
9.5 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20151234",
"Version": "oval:org.altlinux.errata:def:20151234",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-1234: package `sox` update to version 14.4.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-1234",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-1234",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-01677",
"RefURL": "https://bdu.fstec.ru/vul/2023-01677",
"Source": "BDU"
},
{
"RefID": "CVE-2014-8145",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-8145",
"Source": "CVE"
},
{
"RefID": "CVE-2021-3643",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-3643",
"Source": "CVE"
}
],
"Description": "This update upgrades sox to version 14.4.2-alt1. \nSecurity Fix(es):\n\n * BDU:2023-01677: Уязвимость функции lsx_adpcm_init программы обработки звука SoX, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании\n\n * CVE-2014-8145: Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.\n\n * CVE-2021-3643: A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-02-27"
},
"Updated": {
"Date": "2024-04-05"
},
"BDUs": [
{
"ID": "BDU:2023-01677",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2023-01677",
"Impact": "Critical",
"Public": "20210709"
}
],
"CVEs": [
{
"ID": "CVE-2014-8145",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-8145",
"Impact": "High",
"Public": "20141231"
},
{
"ID": "CVE-2021-3643",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-3643",
"Impact": "Critical",
"Public": "20220502"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20151234001",
"Comment": "libsox-devel is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234002",
"Comment": "libsox-devel-static is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234003",
"Comment": "libsox-fmt-alsa is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234004",
"Comment": "libsox-fmt-ao is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234005",
"Comment": "libsox-fmt-caf is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234006",
"Comment": "libsox-fmt-fap is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234007",
"Comment": "libsox-fmt-flac is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234008",
"Comment": "libsox-fmt-gsm is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234009",
"Comment": "libsox-fmt-lpc10 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234010",
"Comment": "libsox-fmt-mat4 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234011",
"Comment": "libsox-fmt-mat5 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234012",
"Comment": "libsox-fmt-mp3 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234013",
"Comment": "libsox-fmt-opus is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234014",
"Comment": "libsox-fmt-oss is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234015",
"Comment": "libsox-fmt-paf is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234016",
"Comment": "libsox-fmt-pulseaudio is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234017",
"Comment": "libsox-fmt-pvf is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234018",
"Comment": "libsox-fmt-sd2 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234019",
"Comment": "libsox-fmt-sndfile is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234020",
"Comment": "libsox-fmt-vorbis is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234021",
"Comment": "libsox-fmt-w64 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234022",
"Comment": "libsox-fmt-wavpack is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234023",
"Comment": "libsox-fmt-xi is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234024",
"Comment": "libsox3 is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234025",
"Comment": "sox is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234026",
"Comment": "sox-base is earlier than 0:14.4.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151234027",
"Comment": "sox-play is earlier than 0:14.4.2-alt1"
}
]
}
]
}
}
]
}