vuln-list-alt/oval/p11/ALT-PU-2024-12685/definitions.json
2024-12-12 21:07:30 +00:00

241 lines
11 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:202412685",
"Version": "oval:org.altlinux.errata:def:202412685",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-12685: package `qt5-imageformats` update to version 5.15.15-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-12685",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-12685",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-03689",
"RefURL": "https://bdu.fstec.ru/vul/2023-03689",
"Source": "BDU"
},
{
"RefID": "BDU:2023-03802",
"RefURL": "https://bdu.fstec.ru/vul/2023-03802",
"Source": "BDU"
},
{
"RefID": "BDU:2023-03803",
"RefURL": "https://bdu.fstec.ru/vul/2023-03803",
"Source": "BDU"
},
{
"RefID": "BDU:2023-05105",
"RefURL": "https://bdu.fstec.ru/vul/2023-05105",
"Source": "BDU"
},
{
"RefID": "BDU:2023-05106",
"RefURL": "https://bdu.fstec.ru/vul/2023-05106",
"Source": "BDU"
},
{
"RefID": "BDU:2023-09121",
"RefURL": "https://bdu.fstec.ru/vul/2023-09121",
"Source": "BDU"
},
{
"RefID": "CVE-2023-32573",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-32573",
"Source": "CVE"
},
{
"RefID": "CVE-2023-32762",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-32762",
"Source": "CVE"
},
{
"RefID": "CVE-2023-32763",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-32763",
"Source": "CVE"
},
{
"RefID": "CVE-2023-34410",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-34410",
"Source": "CVE"
},
{
"RefID": "CVE-2023-37369",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-37369",
"Source": "CVE"
},
{
"RefID": "CVE-2023-38197",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-38197",
"Source": "CVE"
}
],
"Description": "This update upgrades qt5-imageformats to version 5.15.15-alt1. \nSecurity Fix(es):\n\n * BDU:2023-03689: Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю обойти существующие ограничения безопасности\n\n * BDU:2023-03802: Уязвимость компонента QTextLayout кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2023-03803: Уязвимость кроссплатформенного фреймворка для разработки программного обеспечения Qt, связанная с передачей защищаемой информации в незашифрованном виде, позволяющая нарушителю оказать воздействие на целостность данных\n\n * BDU:2023-05105: Уязвимость функции QXmlStreamReader кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2023-05106: Уязвимость функции QSvgFont (Qt SVG) кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2023-09121: Уязвимость функции fastScanName() класса QXmlStreamReader кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2023-32573: In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.\n\n * CVE-2023-32762: An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.\n\n * CVE-2023-32763: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.\n\n * CVE-2023-34410: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.\n\n * CVE-2023-37369: In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.\n\n * CVE-2023-38197: An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-10-17"
},
"Updated": {
"Date": "2024-10-17"
},
"BDUs": [
{
"ID": "BDU:2023-03689",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2023-03689",
"Impact": "Low",
"Public": "20230604"
},
{
"ID": "BDU:2023-03802",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-120",
"Href": "https://bdu.fstec.ru/vul/2023-03802",
"Impact": "High",
"Public": "20230522"
},
{
"ID": "BDU:2023-03803",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-319",
"Href": "https://bdu.fstec.ru/vul/2023-03803",
"Impact": "Low",
"Public": "20230508"
},
{
"ID": "BDU:2023-05105",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://bdu.fstec.ru/vul/2023-05105",
"Impact": "High",
"Public": "20230712"
},
{
"ID": "BDU:2023-05106",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-369",
"Href": "https://bdu.fstec.ru/vul/2023-05106",
"Impact": "Low",
"Public": "20230510"
},
{
"ID": "BDU:2023-09121",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-120",
"Href": "https://bdu.fstec.ru/vul/2023-09121",
"Impact": "High",
"Public": "20230628"
}
],
"CVEs": [
{
"ID": "CVE-2023-32573",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-369",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-32573",
"Impact": "Low",
"Public": "20230510"
},
{
"ID": "CVE-2023-32762",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-32762",
"Impact": "Low",
"Public": "20230528"
},
{
"ID": "CVE-2023-32763",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-120",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-32763",
"Impact": "High",
"Public": "20230528"
},
{
"ID": "CVE-2023-34410",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-34410",
"Impact": "Low",
"Public": "20230605"
},
{
"ID": "CVE-2023-37369",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-37369",
"Impact": "High",
"Public": "20230820"
},
{
"ID": "CVE-2023-38197",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-38197",
"Impact": "High",
"Public": "20230713"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:202412685001",
"Comment": "qt5-imageformats is earlier than 0:5.15.15-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:202412685002",
"Comment": "qt5-imageformats-common is earlier than 0:5.15.15-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:202412685003",
"Comment": "qt5-imageformats-doc is earlier than 0:5.15.15-alt1"
}
]
}
]
}
}
]
}