vuln-list-alt/oval/p11/ALT-PU-2020-2129/definitions.json
2024-12-12 21:07:30 +00:00

160 lines
6.5 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20202129",
"Version": "oval:org.altlinux.errata:def:20202129",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-2129: package `mailman` update to version 2.1.33.0.4.0f97-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-2129",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-2129",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03224",
"RefURL": "https://bdu.fstec.ru/vul/2020-03224",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03997",
"RefURL": "https://bdu.fstec.ru/vul/2020-03997",
"Source": "BDU"
},
{
"RefID": "CVE-2020-12108",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12108",
"Source": "CVE"
},
{
"RefID": "CVE-2020-12137",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12137",
"Source": "CVE"
},
{
"RefID": "CVE-2020-15011",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-15011",
"Source": "CVE"
}
],
"Description": "This update upgrades mailman to version 2.1.33.0.4.0f97-alt1. \nSecurity Fix(es):\n\n * BDU:2020-03224: Уязвимость страницы входа в личный архив Cgi/private.py системы управления почтовыми рассылками GNU Mailman, позволяющая нарушителю внедрить произвольный контент\n\n * BDU:2020-03997: Уязвимость программного обеспечения для управления рассылками электронных писем Mailman, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю оказать воздействие на целостность данных\n\n * CVE-2020-12108: /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.\n\n * CVE-2020-12137: GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME type should have been text/html, and execute JavaScript code.\n\n * CVE-2020-15011: GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.\n\n * #36460: MAILMAN_SITE_LIST = None breaks initial setup",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-06-08"
},
"Updated": {
"Date": "2020-06-08"
},
"BDUs": [
{
"ID": "BDU:2020-03224",
"CVSS": "AV:N/AC:H/Au:N/C:P/I:P/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
"CWE": "CWE-94",
"Href": "https://bdu.fstec.ru/vul/2020-03224",
"Impact": "Low",
"Public": "20200624"
},
{
"ID": "BDU:2020-03997",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2020-03997",
"Impact": "Low",
"Public": "20200424"
}
],
"CVEs": [
{
"ID": "CVE-2020-12108",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"CWE": "CWE-74",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12108",
"Impact": "Low",
"Public": "20200506"
},
{
"ID": "CVE-2020-12137",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12137",
"Impact": "Low",
"Public": "20200424"
},
{
"ID": "CVE-2020-15011",
"CVSS": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"CWE": "CWE-74",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-15011",
"Impact": "Low",
"Public": "20200624"
}
],
"Bugzilla": [
{
"ID": "36460",
"Href": "https://bugzilla.altlinux.org/36460",
"Data": "MAILMAN_SITE_LIST = None breaks initial setup"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20202129001",
"Comment": "mailman is earlier than 5:2.1.33.0.4.0f97-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202129002",
"Comment": "mailman-apache2 is earlier than 5:2.1.33.0.4.0f97-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202129003",
"Comment": "mailman-docs is earlier than 5:2.1.33.0.4.0f97-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202129004",
"Comment": "mailman-nginx is earlier than 5:2.1.33.0.4.0f97-alt1"
}
]
}
]
}
}
]
}