vuln-list-alt/oval/p11/ALT-PU-2022-2026/definitions.json
2024-12-12 21:07:30 +00:00

167 lines
6.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20222026",
"Version": "oval:org.altlinux.errata:def:20222026",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-2026: package `ruby` update to version 2.7.6-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-2026",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-2026",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-03067",
"RefURL": "https://bdu.fstec.ru/vul/2022-03067",
"Source": "BDU"
},
{
"RefID": "BDU:2022-03068",
"RefURL": "https://bdu.fstec.ru/vul/2022-03068",
"Source": "BDU"
},
{
"RefID": "CVE-2022-28738",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-28738",
"Source": "CVE"
},
{
"RefID": "CVE-2022-28739",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-28739",
"Source": "CVE"
}
],
"Description": "This update upgrades ruby to version 2.7.6-alt1. \nSecurity Fix(es):\n\n * BDU:2022-03067: Уязвимость методов алгоритма преобразования строки в число с плавающей запятой Kernel#Float и String#to_f интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2022-03068: Уязвимость реализации класса Regexp интерпретатора языка программирования Ruby, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2022-28738: A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.\n\n * CVE-2022-28739: There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-06-10"
},
"Updated": {
"Date": "2022-06-10"
},
"BDUs": [
{
"ID": "BDU:2022-03067",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-119, CWE-125, CWE-704",
"Href": "https://bdu.fstec.ru/vul/2022-03067",
"Impact": "High",
"Public": "20220412"
},
{
"ID": "BDU:2022-03068",
"CVSS": "AV:L/AC:L/Au:N/C:N/I:C/A:N",
"CVSS3": "AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-119, CWE-415",
"Href": "https://bdu.fstec.ru/vul/2022-03068",
"Impact": "Low",
"Public": "20220412"
}
],
"CVEs": [
{
"ID": "CVE-2022-28738",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-415",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-28738",
"Impact": "Critical",
"Public": "20220509"
},
{
"ID": "CVE-2022-28739",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-28739",
"Impact": "High",
"Public": "20220509"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20222026001",
"Comment": "erb is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026002",
"Comment": "gem is earlier than 2:3.1.6-alt1.5"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026003",
"Comment": "irb is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026004",
"Comment": "libruby is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026005",
"Comment": "libruby-devel is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026006",
"Comment": "libruby-devel-static is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026007",
"Comment": "ri-doc is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026008",
"Comment": "ruby is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026009",
"Comment": "ruby-doc is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026010",
"Comment": "ruby-miniruby-src is earlier than 0:2.7.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222026011",
"Comment": "ruby-stdlibs is earlier than 0:2.7.6-alt1"
}
]
}
]
}
}
]
}