vuln-list-alt/oval/p11/ALT-PU-2023-7818/definitions.json
2024-12-12 21:07:30 +00:00

161 lines
6.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20237818",
"Version": "oval:org.altlinux.errata:def:20237818",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2023-7818: package `libwebkitgtk4.1` update to version 2.42.3-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2023-7818",
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-7818",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-08366",
"RefURL": "https://bdu.fstec.ru/vul/2023-08366",
"Source": "BDU"
},
{
"RefID": "BDU:2023-08367",
"RefURL": "https://bdu.fstec.ru/vul/2023-08367",
"Source": "BDU"
},
{
"RefID": "CVE-2023-42916",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-42916",
"Source": "CVE"
},
{
"RefID": "CVE-2023-42917",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-42917",
"Source": "CVE"
}
],
"Description": "This update upgrades libwebkitgtk4.1 to version 2.42.3-alt1. \nSecurity Fix(es):\n\n * BDU:2023-08366: Уязвимость операционных систем iOS, iPadOS, macOS и браузера Safari, связанная с недостатками контроля доступа, позволяющая нарушителю раскрыть защищаемую информацию\n\n * BDU:2023-08367: Уязвимость модуля отображения веб-страниц WebKit операционных систем iOS, iPadOS, macOS и браузера Safari, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.\n\n * CVE-2023-42917: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2023-12-06"
},
"Updated": {
"Date": "2023-12-06"
},
"BDUs": [
{
"ID": "BDU:2023-08366",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
"CWE": "CWE-200, CWE-266, CWE-284",
"Href": "https://bdu.fstec.ru/vul/2023-08366",
"Impact": "Low",
"Public": "20231130"
},
{
"ID": "BDU:2023-08367",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2023-08367",
"Impact": "Low",
"Public": "20231130"
}
],
"CVEs": [
{
"ID": "CVE-2023-42916",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-42916",
"Impact": "Low",
"Public": "20231130"
},
{
"ID": "CVE-2023-42917",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-42917",
"Impact": "High",
"Public": "20231130"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20237818001",
"Comment": "jsc4.1 is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818002",
"Comment": "libjavascriptcoregtk4.1 is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818003",
"Comment": "libjavascriptcoregtk4.1-devel is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818004",
"Comment": "libjavascriptcoregtk4.1-gir is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818005",
"Comment": "libjavascriptcoregtk4.1-gir-devel is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818006",
"Comment": "libwebkit2gtk4.1 is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818007",
"Comment": "libwebkit2gtk4.1-devel is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818008",
"Comment": "libwebkit2gtk4.1-gir is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818009",
"Comment": "libwebkit2gtk4.1-gir-devel is earlier than 0:2.42.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20237818010",
"Comment": "libwebkitgtk4.1-minibrowser is earlier than 0:2.42.3-alt1"
}
]
}
]
}
}
]
}