2024-04-16 14:26:14 +00:00

133 lines
4.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20212397",
"Version": "oval:org.altlinux.errata:def:20212397",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-2397: package `node` update to version 14.17.4-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-2397",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2397",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-00316",
"RefURL": "https://bdu.fstec.ru/vul/2022-00316",
"Source": "BDU"
},
{
"RefID": "CVE-2021-22930",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22930",
"Source": "CVE"
}
],
"Description": "This update upgrades node to version 14.17.4-alt1. \nSecurity Fix(es):\n\n * BDU:2022-00316: Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2021-22930: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-08-02"
},
"Updated": {
"Date": "2021-08-02"
},
"BDUs": [
{
"ID": "BDU:2022-00316",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2022-00316",
"Impact": "Critical",
"Public": "20211007"
}
],
"CVEs": [
{
"ID": "CVE-2021-22930",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22930",
"Impact": "Critical",
"Public": "20211007"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20212397001",
"Comment": "node is earlier than 0:14.17.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212397002",
"Comment": "node-devel is earlier than 0:14.17.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212397003",
"Comment": "node-doc is earlier than 0:14.17.4-alt1"
}
]
}
]
}
}
]
}