vuln-list-alt/oval/p11/ALT-PU-2020-2259/definitions.json
2024-12-12 21:07:30 +00:00

99 lines
3.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20202259",
"Version": "oval:org.altlinux.errata:def:20202259",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-2259: package `neomutt` update to version 20200626-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-2259",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-2259",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-02007",
"RefURL": "https://bdu.fstec.ru/vul/2021-02007",
"Source": "BDU"
},
{
"RefID": "CVE-2020-14954",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-14954",
"Source": "CVE"
}
],
"Description": "This update upgrades neomutt to version 20200626-alt1. \nSecurity Fix(es):\n\n * BDU:2021-02007: Уязвимость почтовых клиентов Mutt и NeoMutt, связанная с недостатками процедуры нейтрализации особых элементов в выходных данных, используемых входящим компонентом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации\n\n * CVE-2020-14954: Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a \"begin TLS\" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka \"response injection.\"",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-07-02"
},
"Updated": {
"Date": "2020-07-02"
},
"BDUs": [
{
"ID": "BDU:2021-02007",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-74",
"Href": "https://bdu.fstec.ru/vul/2021-02007",
"Impact": "Low",
"Public": "20200619"
}
],
"CVEs": [
{
"ID": "CVE-2020-14954",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-74",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-14954",
"Impact": "Low",
"Public": "20200621"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20202259001",
"Comment": "neomutt is earlier than 0:20200626-alt1"
}
]
}
]
}
}
]
}