vuln-list-alt/oval/p11/ALT-PU-2019-2101/definitions.json
2024-12-12 21:07:30 +00:00

119 lines
4.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20192101",
"Version": "oval:org.altlinux.errata:def:20192101",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-2101: package `bind` update to version 9.11.8-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-2101",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-2101",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01437",
"RefURL": "https://bdu.fstec.ru/vul/2020-01437",
"Source": "BDU"
},
{
"RefID": "CVE-2019-6471",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-6471",
"Source": "CVE"
}
],
"Description": "This update upgrades bind to version 9.11.8-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01437: Уязвимость DNS-сервер BIND, связанная с одновременном выполнением с использованием общего ресурса с неправильной синхронизацией, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-6471: A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion failure in dispatch.c. Versions affected: BIND 9.11.0 -\u003e 9.11.7, 9.12.0 -\u003e 9.12.4-P1, 9.14.0 -\u003e 9.14.2. Also all releases of the BIND 9.13 development branch and version 9.15.0 of the BIND 9.15 development branch and BIND Supported Preview Edition versions 9.11.3-S1 -\u003e 9.11.7-S1.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-06-20"
},
"Updated": {
"Date": "2019-06-20"
},
"BDUs": [
{
"ID": "BDU:2020-01437",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-362",
"Href": "https://bdu.fstec.ru/vul/2020-01437",
"Impact": "Low",
"Public": "20191009"
}
],
"CVEs": [
{
"ID": "CVE-2019-6471",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-362",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-6471",
"Impact": "Low",
"Public": "20191009"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20192101001",
"Comment": "bind is earlier than 0:9.11.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192101002",
"Comment": "bind-devel is earlier than 0:9.11.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192101003",
"Comment": "bind-doc is earlier than 0:9.11.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192101004",
"Comment": "bind-utils is earlier than 0:9.11.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192101005",
"Comment": "libbind is earlier than 0:9.11.8-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192101006",
"Comment": "lwresd is earlier than 0:9.11.8-alt1"
}
]
}
]
}
}
]
}