2024-12-12 21:07:30 +00:00

158 lines
6.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20222231",
"Version": "oval:org.altlinux.errata:def:20222231",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-2231: package `git` update to version 2.33.4-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-2231",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-2231",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-04385",
"RefURL": "https://bdu.fstec.ru/vul/2022-04385",
"Source": "BDU"
},
{
"RefID": "CVE-2022-29187",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-29187",
"Source": "CVE"
}
],
"Description": "This update upgrades git to version 2.33.4-alt1. \nSecurity Fix(es):\n\n * BDU:2022-04385: Уязвимость распределенной системы управления версиями Git, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии или выполнить произвольные команды\n\n * CVE-2022-29187: Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could still be affected by the issue reported in CVE-2022-24765, for example when navigating as root into a shared tmp directory that is owned by them, but where an attacker could create a git repository. Versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5 contain a patch for this issue. The simplest way to avoid being affected by the exploit described in the example is to avoid running git as root (or an Administrator in Windows), and if needed to reduce its use to a minimum. While a generic workaround is not possible, a system could be hardened from the exploit described in the example by removing any such repository if it exists already and creating one as root to block any future attacks.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-07-12"
},
"Updated": {
"Date": "2022-07-12"
},
"BDUs": [
{
"ID": "BDU:2022-04385",
"CVSS": "AV:L/AC:L/Au:S/C:C/I:C/A:P",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-282, CWE-427",
"Href": "https://bdu.fstec.ru/vul/2022-04385",
"Impact": "High",
"Public": "20220712"
}
],
"CVEs": [
{
"ID": "CVE-2022-29187",
"CVSS": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-29187",
"Impact": "High",
"Public": "20220712"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20222231001",
"Comment": "git is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231002",
"Comment": "git-arch is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231003",
"Comment": "git-contrib is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231004",
"Comment": "git-core is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231005",
"Comment": "git-cvs is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231006",
"Comment": "git-diff-highlight is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231007",
"Comment": "git-doc is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231008",
"Comment": "git-email is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231009",
"Comment": "git-full is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231010",
"Comment": "git-gui is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231011",
"Comment": "git-server is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231012",
"Comment": "git-subtree is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231013",
"Comment": "git-svn is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231014",
"Comment": "gitk is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231015",
"Comment": "gitweb is earlier than 0:2.33.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222231016",
"Comment": "perl-Git is earlier than 0:2.33.4-alt1"
}
]
}
]
}
}
]
}