vuln-list-alt/oval/p11/ALT-PU-2020-1898/definitions.json
2024-12-12 21:07:30 +00:00

159 lines
6.5 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20201898",
"Version": "oval:org.altlinux.errata:def:20201898",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-1898: package `roundcube` update to version 1.4.4-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-1898",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1898",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03991",
"RefURL": "https://bdu.fstec.ru/vul/2020-03991",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03992",
"RefURL": "https://bdu.fstec.ru/vul/2020-03992",
"Source": "BDU"
},
{
"RefID": "CVE-2020-12625",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12625",
"Source": "CVE"
},
{
"RefID": "CVE-2020-12626",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12626",
"Source": "CVE"
},
{
"RefID": "CVE-2020-12640",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12640",
"Source": "CVE"
},
{
"RefID": "CVE-2020-12641",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12641",
"Source": "CVE"
}
],
"Description": "This update upgrades roundcube to version 1.4.4-alt1. \nSecurity Fix(es):\n\n * BDU:2020-03991: Уязвимость решения для IMAP-серверов на основе AJAX Roundcube, связанная с недостатками механизмов противодействия межсайтовой фальсификации, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-03992: Уязвимость решения для IMAP-серверов на основе AJAX Roundcube, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных\n\n * CVE-2020-12625: An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.php because JavaScript code can occur in the CDATA of an HTML message.\n\n * CVE-2020-12626: An issue was discovered in Roundcube Webmail before 1.4.4. A CSRF attack can cause an authenticated user to be logged out because POST was not considered.\n\n * CVE-2020-12640: Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name to rcube_plugin_api.php.\n\n * CVE-2020-12641: rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-04-30"
},
"Updated": {
"Date": "2020-04-30"
},
"BDUs": [
{
"ID": "BDU:2020-03991",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-352",
"Href": "https://bdu.fstec.ru/vul/2020-03991",
"Impact": "Low",
"Public": "20200503"
},
{
"ID": "BDU:2020-03992",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2020-03992",
"Impact": "Low",
"Public": "20200503"
}
],
"CVEs": [
{
"ID": "CVE-2020-12625",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12625",
"Impact": "Low",
"Public": "20200504"
},
{
"ID": "CVE-2020-12626",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-352",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12626",
"Impact": "Low",
"Public": "20200504"
},
{
"ID": "CVE-2020-12640",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12640",
"Impact": "Critical",
"Public": "20200504"
},
{
"ID": "CVE-2020-12641",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-78",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12641",
"Impact": "Critical",
"Public": "20200504"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20201898001",
"Comment": "roundcube is earlier than 0:1.4.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201898002",
"Comment": "roundcube-apache2 is earlier than 0:1.4.4-alt1"
}
]
}
]
}
}
]
}