2024-12-12 21:07:30 +00:00

135 lines
5.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20202220",
"Version": "oval:org.altlinux.errata:def:20202220",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-2220: package `python3` update to version 3.8.3-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-2220",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-2220",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-03715",
"RefURL": "https://bdu.fstec.ru/vul/2021-03715",
"Source": "BDU"
},
{
"RefID": "CVE-2019-18348",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-18348",
"Source": "CVE"
}
],
"Description": "This update upgrades python3 to version 3.8.3-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03715: Уязвимость модуля urllib2 языка программирования Python, связанная с недостаточной нейтрализацией специальных элементов в запросе, позволяющая нарушителю оказать воздействие на целостность данных\n\n * CVE-2019-18348: An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \\r\\n (specifically in the host component of a URL) followed by an HTTP header. This is similar to the CVE-2019-9740 query string issue and the CVE-2019-9947 path string issue. (This is not exploitable when glibc has CVE-2016-10739 fixed.). This is fixed in: v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1; v3.6.11, v3.6.11rc1, v3.6.12; v3.7.8, v3.7.8rc1, v3.7.9; v3.8.3, v3.8.3rc1, v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-06-21"
},
"Updated": {
"Date": "2020-06-21"
},
"BDUs": [
{
"ID": "BDU:2021-03715",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-74",
"Href": "https://bdu.fstec.ru/vul/2021-03715",
"Impact": "Low",
"Public": "20191023"
}
],
"CVEs": [
{
"ID": "CVE-2019-18348",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-74",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-18348",
"Impact": "Low",
"Public": "20191023"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20202220001",
"Comment": "libpython3 is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220002",
"Comment": "python3 is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220003",
"Comment": "python3-base is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220004",
"Comment": "python3-dev is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220005",
"Comment": "python3-modules-curses is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220006",
"Comment": "python3-modules-nis is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220007",
"Comment": "python3-modules-sqlite3 is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220008",
"Comment": "python3-modules-tkinter is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220009",
"Comment": "python3-test is earlier than 0:3.8.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202220010",
"Comment": "python3-tools is earlier than 0:3.8.3-alt1"
}
]
}
]
}
}
]
}