vuln-list-alt/oval/p11/ALT-PU-2022-2575/definitions.json
2024-12-12 21:07:30 +00:00

133 lines
5.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20222575",
"Version": "oval:org.altlinux.errata:def:20222575",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-2575: package `zoneminder` update to version 1.36.25-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-2575",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-2575",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-01774",
"RefURL": "https://bdu.fstec.ru/vul/2023-01774",
"Source": "BDU"
},
{
"RefID": "CVE-2022-29806",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-29806",
"Source": "CVE"
},
{
"RefID": "CVE-2022-30768",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-30768",
"Source": "CVE"
},
{
"RefID": "CVE-2022-30769",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-30769",
"Source": "CVE"
}
],
"Description": "This update upgrades zoneminder to version 1.36.25-alt1. \nSecurity Fix(es):\n\n * BDU:2023-01774: Уязвимость программного обеспечения для организации видеонаблюдения ZoneMinder, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2022-29806: ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.\n\n * CVE-2022-30768: A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code via the Username field when an Admin (or non-Admin users that can see other users logged into the platform) clicks on Logout. NOTE: this exists in later versions than CVE-2019-7348 and requires a different attack method.\n\n * CVE-2022-30769: Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in user.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-09-07"
},
"Updated": {
"Date": "2022-09-07"
},
"BDUs": [
{
"ID": "BDU:2023-01774",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2023-01774",
"Impact": "Critical",
"Public": "20220208"
}
],
"CVEs": [
{
"ID": "CVE-2022-29806",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-29806",
"Impact": "Critical",
"Public": "20220426"
},
{
"ID": "CVE-2022-30768",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-30768",
"Impact": "Low",
"Public": "20221115"
},
{
"ID": "CVE-2022-30769",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
"CWE": "CWE-384",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-30769",
"Impact": "Low",
"Public": "20221115"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20222575001",
"Comment": "zoneminder is earlier than 0:1.36.25-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222575002",
"Comment": "zoneminder-api is earlier than 0:1.36.25-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222575003",
"Comment": "zoneminder-nginx is earlier than 0:1.36.25-alt1"
}
]
}
]
}
}
]
}