2024-12-12 21:07:30 +00:00

115 lines
4.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172154",
"Version": "oval:org.altlinux.errata:def:20172154",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2154: package `lxc` update to version 2.1.0-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2154",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2154",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01714",
"RefURL": "https://bdu.fstec.ru/vul/2020-01714",
"Source": "BDU"
},
{
"RefID": "CVE-2018-6556",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-6556",
"Source": "CVE"
}
],
"Description": "This update upgrades lxc to version 2.1.0-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01714: Уязвимость системы виртуализации LXC, связанная с ошибкой предоставления пользователю доступа, при запросе удаления сетевого интерфейса, позволяющая нарушителю получить доступ к конфиденциальным данным\n\n * CVE-2018-6556: lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-09-07"
},
"Updated": {
"Date": "2017-09-07"
},
"BDUs": [
{
"ID": "BDU:2020-01714",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-417",
"Href": "https://bdu.fstec.ru/vul/2020-01714",
"Impact": "Low",
"Public": "20180810"
}
],
"CVEs": [
{
"ID": "CVE-2018-6556",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-417",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-6556",
"Impact": "Low",
"Public": "20180810"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172154001",
"Comment": "lxc is earlier than 0:2.1.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172154002",
"Comment": "lxc-devel is earlier than 0:2.1.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172154003",
"Comment": "lxc-libs is earlier than 0:2.1.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172154004",
"Comment": "lxc-sysvinit is earlier than 0:2.1.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172154005",
"Comment": "python3-module-lxc is earlier than 0:2.1.0-alt1"
}
]
}
]
}
}
]
}