vuln-list-alt/oval/p11/ALT-PU-2015-2011/definitions.json
2024-12-12 21:07:30 +00:00

97 lines
3.5 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20152011",
"Version": "oval:org.altlinux.errata:def:20152011",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-2011: package `kernel-modules-nvidia-un-def` update to version 352.55-alt1.262912.1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-2011",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-2011",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-12100",
"RefURL": "https://bdu.fstec.ru/vul/2015-12100",
"Source": "BDU"
},
{
"RefID": "CVE-2015-5053",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5053",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-modules-nvidia-un-def to version 352.55-alt1.262912.1. \nSecurity Fix(es):\n\n * BDU:2015-12100: Уязвимость программного обеспечения графического процессора NVIDIA GPU, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании\n\n * CVE-2015-5053: The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-11-18"
},
"Updated": {
"Date": "2015-11-18"
},
"BDUs": [
{
"ID": "BDU:2015-12100",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-284",
"Href": "https://bdu.fstec.ru/vul/2015-12100",
"Impact": "Critical",
"Public": "20151124"
}
],
"CVEs": [
{
"ID": "CVE-2015-5053",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-284",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5053",
"Impact": "Critical",
"Public": "20151124"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20152011001",
"Comment": "kernel-modules-nvidia-un-def is earlier than 0:352.55-alt1.262912.1"
}
]
}
]
}
}
]
}