vuln-list-alt/oval/p11/ALT-PU-2017-1857/definitions.json
2024-12-12 21:07:30 +00:00

175 lines
7.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20171857",
"Version": "oval:org.altlinux.errata:def:20171857",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-1857: package `samba-DC` update to version 4.6.6-alt1.S1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-1857",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-1857",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-01424",
"RefURL": "https://bdu.fstec.ru/vul/2021-01424",
"Source": "BDU"
},
{
"RefID": "CVE-2017-11103",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-11103",
"Source": "CVE"
}
],
"Description": "This update upgrades samba-DC to version 4.6.6-alt1.S1. \nSecurity Fix(es):\n\n * BDU:2021-01424: Уязвимость функции _krb5_extract_ticket() пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма проверки подлинности данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2017-11103: Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-07-13"
},
"Updated": {
"Date": "2017-07-13"
},
"BDUs": [
{
"ID": "BDU:2021-01424",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-345",
"Href": "https://bdu.fstec.ru/vul/2021-01424",
"Impact": "High",
"Public": "20170713"
}
],
"CVEs": [
{
"ID": "CVE-2017-11103",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-345",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-11103",
"Impact": "High",
"Public": "20170713"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20171857001",
"Comment": "libldb-modules-DC is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857002",
"Comment": "libwbclient-DC is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857003",
"Comment": "libwbclient-DC-devel is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857004",
"Comment": "python-module-samba-DC is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857005",
"Comment": "samba-DC is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857006",
"Comment": "samba-DC-client is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857007",
"Comment": "samba-DC-common is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857008",
"Comment": "samba-DC-common-libs is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857009",
"Comment": "samba-DC-ctdb is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857010",
"Comment": "samba-DC-ctdb-tests is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857011",
"Comment": "samba-DC-devel is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857012",
"Comment": "samba-DC-doc is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857013",
"Comment": "samba-DC-libs is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857014",
"Comment": "samba-DC-pidl is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857015",
"Comment": "samba-DC-test is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857016",
"Comment": "samba-DC-util-private-headers is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857017",
"Comment": "samba-DC-winbind is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857018",
"Comment": "samba-DC-winbind-clients is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857019",
"Comment": "samba-DC-winbind-krb5-locator is earlier than 0:4.6.6-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20171857020",
"Comment": "task-samba-dc is earlier than 0:4.6.6-alt1.S1"
}
]
}
]
}
}
]
}