vuln-list-alt/oval/p11/ALT-PU-2020-1668/definitions.json
2024-12-12 21:07:30 +00:00

139 lines
5.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20201668",
"Version": "oval:org.altlinux.errata:def:20201668",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-1668: package `coturn` update to version 4.5.1.1-alt2",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-1668",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1668",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03979",
"RefURL": "https://bdu.fstec.ru/vul/2020-03979",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03980",
"RefURL": "https://bdu.fstec.ru/vul/2020-03980",
"Source": "BDU"
},
{
"RefID": "CVE-2020-6061",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-6061",
"Source": "CVE"
},
{
"RefID": "CVE-2020-6062",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-6062",
"Source": "CVE"
}
],
"Description": "This update upgrades coturn to version 4.5.1.1-alt2. \nSecurity Fix(es):\n\n * BDU:2020-03979: Уязвимость веб-сервера Coturn, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-03980: Уязвимость веб-сервера Coturn, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2020-6061: An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.\n\n * CVE-2020-6062: An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-04-05"
},
"Updated": {
"Date": "2020-04-05"
},
"BDUs": [
{
"ID": "BDU:2020-03979",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2020-03979",
"Impact": "High",
"Public": "20200219"
},
{
"ID": "BDU:2020-03980",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2020-03980",
"Impact": "Critical",
"Public": "20200219"
}
],
"CVEs": [
{
"ID": "CVE-2020-6061",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-6061",
"Impact": "Critical",
"Public": "20200219"
},
{
"ID": "CVE-2020-6062",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-6062",
"Impact": "High",
"Public": "20200219"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20201668001",
"Comment": "coturn is earlier than 0:4.5.1.1-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201668002",
"Comment": "coturn-client-devel is earlier than 0:4.5.1.1-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201668003",
"Comment": "coturn-client-libs is earlier than 0:4.5.1.1-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201668004",
"Comment": "coturn-utils is earlier than 0:4.5.1.1-alt2"
}
]
}
]
}
}
]
}