2024-04-16 14:26:14 +00:00

1111 lines
77 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20223073",
"Version": "oval:org.altlinux.errata:def:20223073",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-3073: package `node` update to version 16.17.1-alt0.c9.1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-3073",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-3073",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03621",
"RefURL": "https://bdu.fstec.ru/vul/2020-03621",
"Source": "BDU"
},
{
"RefID": "BDU:2020-04460",
"RefURL": "https://bdu.fstec.ru/vul/2020-04460",
"Source": "BDU"
},
{
"RefID": "BDU:2020-04461",
"RefURL": "https://bdu.fstec.ru/vul/2020-04461",
"Source": "BDU"
},
{
"RefID": "BDU:2020-05054",
"RefURL": "https://bdu.fstec.ru/vul/2020-05054",
"Source": "BDU"
},
{
"RefID": "BDU:2020-05657",
"RefURL": "https://bdu.fstec.ru/vul/2020-05657",
"Source": "BDU"
},
{
"RefID": "BDU:2020-05687",
"RefURL": "https://bdu.fstec.ru/vul/2020-05687",
"Source": "BDU"
},
{
"RefID": "BDU:2021-00872",
"RefURL": "https://bdu.fstec.ru/vul/2021-00872",
"Source": "BDU"
},
{
"RefID": "BDU:2021-00883",
"RefURL": "https://bdu.fstec.ru/vul/2021-00883",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01024",
"RefURL": "https://bdu.fstec.ru/vul/2021-01024",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01025",
"RefURL": "https://bdu.fstec.ru/vul/2021-01025",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01844",
"RefURL": "https://bdu.fstec.ru/vul/2021-01844",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01895",
"RefURL": "https://bdu.fstec.ru/vul/2021-01895",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01896",
"RefURL": "https://bdu.fstec.ru/vul/2021-01896",
"Source": "BDU"
},
{
"RefID": "BDU:2021-03700",
"RefURL": "https://bdu.fstec.ru/vul/2021-03700",
"Source": "BDU"
},
{
"RefID": "BDU:2021-03742",
"RefURL": "https://bdu.fstec.ru/vul/2021-03742",
"Source": "BDU"
},
{
"RefID": "BDU:2021-04210",
"RefURL": "https://bdu.fstec.ru/vul/2021-04210",
"Source": "BDU"
},
{
"RefID": "BDU:2021-04995",
"RefURL": "https://bdu.fstec.ru/vul/2021-04995",
"Source": "BDU"
},
{
"RefID": "BDU:2021-04996",
"RefURL": "https://bdu.fstec.ru/vul/2021-04996",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00115",
"RefURL": "https://bdu.fstec.ru/vul/2022-00115",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00201",
"RefURL": "https://bdu.fstec.ru/vul/2022-00201",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00226",
"RefURL": "https://bdu.fstec.ru/vul/2022-00226",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00316",
"RefURL": "https://bdu.fstec.ru/vul/2022-00316",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00342",
"RefURL": "https://bdu.fstec.ru/vul/2022-00342",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00758",
"RefURL": "https://bdu.fstec.ru/vul/2022-00758",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00760",
"RefURL": "https://bdu.fstec.ru/vul/2022-00760",
"Source": "BDU"
},
{
"RefID": "BDU:2022-01315",
"RefURL": "https://bdu.fstec.ru/vul/2022-01315",
"Source": "BDU"
},
{
"RefID": "BDU:2022-01889",
"RefURL": "https://bdu.fstec.ru/vul/2022-01889",
"Source": "BDU"
},
{
"RefID": "BDU:2022-01892",
"RefURL": "https://bdu.fstec.ru/vul/2022-01892",
"Source": "BDU"
},
{
"RefID": "BDU:2022-02171",
"RefURL": "https://bdu.fstec.ru/vul/2022-02171",
"Source": "BDU"
},
{
"RefID": "BDU:2022-02880",
"RefURL": "https://bdu.fstec.ru/vul/2022-02880",
"Source": "BDU"
},
{
"RefID": "BDU:2022-03022",
"RefURL": "https://bdu.fstec.ru/vul/2022-03022",
"Source": "BDU"
},
{
"RefID": "BDU:2022-03042",
"RefURL": "https://bdu.fstec.ru/vul/2022-03042",
"Source": "BDU"
},
{
"RefID": "BDU:2022-04390",
"RefURL": "https://bdu.fstec.ru/vul/2022-04390",
"Source": "BDU"
},
{
"RefID": "BDU:2023-00348",
"RefURL": "https://bdu.fstec.ru/vul/2023-00348",
"Source": "BDU"
},
{
"RefID": "CVE-2020-11080",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-11080",
"Source": "CVE"
},
{
"RefID": "CVE-2020-1971",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1971",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8172",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8172",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8174",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8174",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8201",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8201",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8251",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8251",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8252",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8252",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8265",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8265",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8277",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8277",
"Source": "CVE"
},
{
"RefID": "CVE-2020-8287",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-8287",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22883",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22883",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22884",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22884",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22918",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22918",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22930",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22930",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22931",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22931",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22939",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22939",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22940",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22940",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22959",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22959",
"Source": "CVE"
},
{
"RefID": "CVE-2021-22960",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-22960",
"Source": "CVE"
},
{
"RefID": "CVE-2021-23840",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-23840",
"Source": "CVE"
},
{
"RefID": "CVE-2021-32803",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-32803",
"Source": "CVE"
},
{
"RefID": "CVE-2021-32804",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-32804",
"Source": "CVE"
},
{
"RefID": "CVE-2021-3449",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-3449",
"Source": "CVE"
},
{
"RefID": "CVE-2021-3672",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-3672",
"Source": "CVE"
},
{
"RefID": "CVE-2021-37701",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-37701",
"Source": "CVE"
},
{
"RefID": "CVE-2021-37712",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-37712",
"Source": "CVE"
},
{
"RefID": "CVE-2021-37713",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-37713",
"Source": "CVE"
},
{
"RefID": "CVE-2021-39134",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-39134",
"Source": "CVE"
},
{
"RefID": "CVE-2021-39135",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-39135",
"Source": "CVE"
},
{
"RefID": "CVE-2021-44531",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-44531",
"Source": "CVE"
},
{
"RefID": "CVE-2021-44532",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-44532",
"Source": "CVE"
},
{
"RefID": "CVE-2021-44533",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-44533",
"Source": "CVE"
},
{
"RefID": "CVE-2022-0778",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-0778",
"Source": "CVE"
},
{
"RefID": "CVE-2022-21824",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-21824",
"Source": "CVE"
},
{
"RefID": "CVE-2022-32212",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-32212",
"Source": "CVE"
},
{
"RefID": "CVE-2022-32213",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-32213",
"Source": "CVE"
},
{
"RefID": "CVE-2022-32214",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-32214",
"Source": "CVE"
},
{
"RefID": "CVE-2022-32215",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-32215",
"Source": "CVE"
},
{
"RefID": "CVE-2022-35255",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-35255",
"Source": "CVE"
},
{
"RefID": "CVE-2022-35256",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-35256",
"Source": "CVE"
}
],
"Description": "This update upgrades node to version 16.17.1-alt0.c9.1. \nSecurity Fix(es):\n\n * BDU:2020-03621: Уязвимость реализации протокола TLS программной платформы Node.js, позволяющая нарушителю реализовать атаку типа «человек посередине»\n\n * BDU:2020-04460: Уязвимость функций napi_get_value_string_latin1(), napi_get_value_string_utf8(), napi_get_value_string_utf16() программной платформы Node.js, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2020-04461: Уязвимость библиотеки nghttp2, связанная с ошибками при использовании выделенной памяти при обработке пакетов HTTP/2 SETTINGS, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-05054: Уязвимость компонента Cluster: JS module (Node.js) системы управления базами данных Oracle MySQL Cluster, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2020-05657: Уязвимость программной платформы Node.js, связанная с ошибкой обработки имен HTTP - заголовка, позволяющая нарушителю получить доступ к защищаемой информации или повысить свои привилегии\n\n * BDU:2020-05687: Уязвимость программной платформы Node.js, связанная с ошибкой обработки имен HTTP - заголовка, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-00872: Уязвимость функции GENERAL_NAME_cmp библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-00883: Уязвимость реализации метода DoWrite программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие\n\n * BDU:2021-01024: Уязвимость программной платформы Node.js, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-01025: Уязвимость программной платформы Node.js, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации\n\n * BDU:2021-01844: Уязвимость реализации протокола TLS библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-01895: Уязвимость программной платформы Node.js, связанная с присутствием localhost6 в белом списке, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2021-01896: Уязвимость программной платформы Node.js, связанная с ошибкой механизма контроля расходуемых ресурсов, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-03700: Уязвимость функции uv__idna_toascii() программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к защищаемой информации\n\n * BDU:2021-03742: Уязвимость функций EVP_CipherUpdate, EVP_EncryptUpdate и EVP_DecryptUpdate инструментария для протоколов TLS и SSL OpenSSL, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-04210: Уязвимость функции uv__idna_toascii() программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании\n\n * BDU:2021-04995: Уязвимость компонента LLHTTP программного средства работы с объектами NodeJS, позволяющая нарушителю повысить свои привилегии\n\n * BDU:2021-04996: Уязвимость компонента LLHTTP программного средства работы с объектами NodeJS, позволяющая нарушителю повысить свои привилегии\n\n * BDU:2022-00115: Уязвимость библиотеки `@ npmcli / arborist` пакетного менеджера NPM, позволяющая нарушителю перезаписать файлы через манипуляцию с символическими ссылками\n\n * BDU:2022-00201: Уязвимость метода модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании\n\n * BDU:2022-00226: Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании\n\n * BDU:2022-00316: Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2022-00342: Уязвимость библиотеки СИ для асинхронных запросов DNS c-ares, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2022-00758: Уязвимость реализации способа указания всех доменных имен и IP-адресов Subject Alternative Names программной платформы Node.js, позволяющая нарушителю проводить спуфинг-атаки\n\n * BDU:2022-00760: Уязвимость реализации функции console.table() программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании или обойти ограничения безопасности\n\n * BDU:2022-01315: Уязвимость функции BN_mod_sqrt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2022-01889: Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать воздействие на целостность данных\n\n * BDU:2022-01892: Уязвимость библиотеки dns программной платформы Node.js, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2022-02171: Уязвимость компонента API https программной платформы Node.js, позволяющая нарушителю оказать воздействие на целостность данных\n\n * BDU:2022-02880: Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю загрузить произвольные файлы и выполнить произвольный код\n\n * BDU:2022-03022: Уязвимость модуля Node.js для обработки tar архивов Node-tar, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю создать, перезаписать произвольные файлы и выполнить произвольный код\n\n * BDU:2022-03042: Уязвимость модуля Node-tar библиотеки Node.js, позволяющая нарушителю записывать произвольные файлы или выполнить произвольный код\n\n * BDU:2022-04390: Уязвимость программной платформы Node.js, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю выполнять атаку \u0026quot;контрабанда HTTP-запросов\u0026quot;\n\n * BDU:2023-00348: Уязвимость анализатора HTTP-кода llhttp программного обеспечения для управления сетевой инфраструктурой SINEC INS (Infrastructure Network Services), позволяющая нарушителю выполнить произвольный код\n\n * CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., \u003e 32), then drop the connection.\n\n * CVE-2020-1971: The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious certificate against a malicious CRL then this may occur. Note that some applications automatically download CRLs based on a URL embedded in a certificate. This checking happens prior to the signatures on the certificate and CRL being verified. OpenSSL's s_server, s_client and verify tools have support for the \"-crl_download\" option which implements automatic CRL downloading and this attack has been demonstrated to work against those tools. Note that an unrelated bug means that affected versions of OpenSSL cannot parse or construct correct encodings of EDIPARTYNAME. However it is possible to construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence trigger this attack. All OpenSSL 1.1.1 and 1.0.2 versions are affected by this issue. Other OpenSSL releases are out of support and have not been checked. Fixed in OpenSSL 1.1.1i (Affected 1.1.1-1.1.1h). Fixed in OpenSSL 1.0.2x (Affected 1.0.2-1.0.2w).\n\n * CVE-2020-8172: TLS session reuse can lead to host certificate verification bypass in node version \u003c 12.18.0 and \u003c 14.4.0.\n\n * CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node \u003c 10.21.0, 12.18.0, and \u003c 14.4.0.\n\n * CVE-2020-8201: Node.js \u003c 12.18.4 and \u003c 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names.\n\n * CVE-2020-8251: Node.js \u003c 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.\n\n * CVE-2020-8252: The implementation of realpath in libuv \u003c 10.22.1, \u003c 12.18.4, and \u003c 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.\n\n * CVE-2020-8265: Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.\n\n * CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions \u003c 15.2.1, \u003c 14.15.1, and \u003c 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.\n\n * CVE-2020-8287: Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling.\n\n * CVE-2021-22883: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.\n\n * CVE-2021-22884: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.\n\n * CVE-2021-22918: Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to convert strings to ASCII. The pointer p is read and increased without checking whether it is beyond pe, with the latter holding a pointer to the end of the buffer. This can lead to information disclosures or crashes. This function can be triggered via uv_getaddrinfo().\n\n * CVE-2021-22930: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.\n\n * CVE-2021-22931: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.\n\n * CVE-2021-22939: If the Node.js https API was used incorrectly and \"undefined\" was in passed for the \"rejectUnauthorized\" parameter, no error was returned and connections to servers with an expired certificate would have been accepted.\n\n * CVE-2021-22940: Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.\n\n * CVE-2021-22959: The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp \u003c v2.1.4 and \u003c v6.0.6.\n\n * CVE-2021-22960: The parse function in llhttp \u003c 2.1.4 and \u003c 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.\n\n * CVE-2021-23840: Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).\n\n * CVE-2021-32803: The npm package \"tar\" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary `stat` calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory. This order of operations resulted in the directory being created and added to the `node-tar` directory cache. When a directory is present in the directory cache, subsequent calls to mkdir for that directory are skipped. However, this is also where `node-tar` checks for symlinks occur. By first creating a directory, and then replacing that directory with a symlink, it was thus possible to bypass `node-tar` symlink checks on directories, essentially allowing an untrusted tar file to symlink into an arbitrary location and subsequently extracting arbitrary files into that location, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.3, 4.4.15, 5.0.7 and 6.1.2.\n\n * CVE-2021-32804: The npm package \"tar\" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file paths by turning absolute paths into relative paths when the `preservePaths` flag is not set to `true`. This is achieved by stripping the absolute path root from any absolute file paths contained in a tar file. For example `/home/user/.bashrc` would turn into `home/user/.bashrc`. This logic was insufficient when file paths contained repeated path roots such as `////home/user/.bashrc`. `node-tar` would only strip a single path root from such paths. When given an absolute file path with repeating path roots, the resulting path (e.g. `///home/user/.bashrc`) would still resolve to an absolute path, thus allowing arbitrary file creation and overwrite. This issue was addressed in releases 3.2.2, 4.4.14, 5.0.6 and 6.1.1. Users may work around this vulnerability without upgrading by creating a custom `onentry` method which sanitizes the `entry.path` or a `filter` method which removes entries with absolute paths. See referenced GitHub Advisory for details. Be aware of CVE-2021-32803 which fixes a similar bug in later versions of tar.\n\n * CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).\n\n * CVE-2021-3672: A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.\n\n * CVE-2021-37701: The npm package \"tar\" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with the same name as the directory, where the symlink and directory names in the archive entry used backslashes as a path separator on posix systems. The cache checking logic used both `\\` and `/` characters as path separators, however `\\` is a valid filename character on posix systems. By first creating a directory, and then replacing that directory with a symlink, it was thus possible to bypass node-tar symlink checks on directories, essentially allowing an untrusted tar file to symlink into an arbitrary location and subsequently extracting arbitrary files into that location, thus allowing arbitrary file creation and overwrite. Additionally, a similar confusion could arise on case-insensitive filesystems. If a tar archive contained a directory at `FOO`, followed by a symbolic link named `foo`, then on case-insensitive file systems, the creation of the symbolic link would remove the directory from the filesystem, but _not_ from the internal directory cache, as it would not be treated as a cache hit. A subsequent file entry within the `FOO` directory would then be placed in the target of the symbolic link, thinking that the directory had already been created. These issues were addressed in releases 4.4.16, 5.0.8 and 6.1.7. The v3 branch of node-tar has been deprecated and did not receive patches for these issues. If you are still using a v3 release we recommend you update to a more recent version of node-tar. If this is not possible, a workaround is available in the referenced GHSA-9r2w-394v-53qc.\n\n * CVE-2021-37712: The npm package \"tar\" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by a symbolic link is not extracted. This is, in part, achieved by ensuring that extracted directories are not symlinks. Additionally, in order to prevent unnecessary stat calls to determine whether a given path is a directory, paths are cached when directories are created. This logic was insufficient when extracting tar files that contained both a directory and a symlink with names containing unicode values that normalized to the same value. Additionally, on Windows systems, long path portions would resolve to the same file system entities as their 8.3 \"short path\" counterparts. A specially crafted tar archive could thus include a directory with one form of the path, followed by a symbolic link with a different string that resolves to the same file system entity, followed by a file using the first form. By first creating a directory, and then replacing that directory with a symlink that had a different apparent name that resolved to the same entry in the filesystem, it was thus possible to bypass node-tar symlink checks on directories, essentially allowing an untrusted tar file to symlink into an arbitrary location and subsequently extracting arbitrary files into that location, thus allowing arbitrary file creation and overwrite. These issues were addressed in releases 4.4.18, 5.0.10 and 6.1.9. The v3 branch of node-tar has been deprecated and did not receive patches for these issues. If you are still using a v3 release we recommend you update to a more recent version of node-tar. If this is not possible, a workaround is available in the referenced GHSA-qq89-hq3f-393p.\n\n * CVE-2021-37713: The npm package \"tar\" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part, accomplished by sanitizing absolute paths of entries within the archive, skipping archive entries that contain `..` path portions, and resolving the sanitized paths against the extraction target directory. This logic was insufficient on Windows systems when extracting tar files that contained a path that was not an absolute path, but specified a drive letter different from the extraction target, such as `C:some\\path`. If the drive letter does not match the extraction target, for example `D:\\extraction\\dir`, then the result of `path.resolve(extractionDirectory, entryPath)` would resolve against the current working directory on the `C:` drive, rather than the extraction target directory. Additionally, a `..` portion of the path could occur immediately after the drive letter, such as `C:../foo`, and was not properly sanitized by the logic that checked for `..` within the normalized and split portions of the path. This only affects users of `node-tar` on Windows systems. These issues were addressed in releases 4.4.18, 5.0.10 and 6.1.9. The v3 branch of node-tar has been deprecated and did not receive patches for these issues. If you are still using a v3 release we recommend you update to a more recent version of node-tar. There is no reasonable way to work around this issue without performing the same path normalization procedures that node-tar now does. Users are encouraged to upgrade to the latest patched versions of node-tar, rather than attempt to sanitize paths themselves.\n\n * CVE-2021-39134: `@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is, in part, accomplished by resolving dependency specifiers defined in `package.json` manifests for dependencies with a specific name, and nesting folders to resolve conflicting dependencies. When multiple dependencies differ only in the case of their name, Arborist's internal data structure saw them as separate items that could coexist within the same level in the `node_modules` hierarchy. However, on case-insensitive file systems (such as macOS and Windows), this is not the case. Combined with a symlink dependency such as `file:/some/path`, this allowed an attacker to create a situation in which arbitrary contents could be written to any location on the filesystem. For example, a package `pwn-a` could define a dependency in their `package.json` file such as `\"foo\": \"file:/some/path\"`. Another package, `pwn-b` could define a dependency such as `FOO: \"file:foo.tgz\"`. On case-insensitive file systems, if `pwn-a` was installed, and then `pwn-b` was installed afterwards, the contents of `foo.tgz` would be written to `/some/path`, and any existing contents of `/some/path` would be removed. Anyone using npm v7.20.6 or earlier on a case-insensitive filesystem is potentially affected. This is patched in @npmcli/arborist 2.8.2 which is included in npm v7.20.7 and above.\n\n * CVE-2021-39135: `@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the npm command line interface, aims to guarantee that package dependency contracts will be met, and the extraction of package contents will always be performed into the expected folder. This is accomplished by extracting package contents into a project's `node_modules` folder. If the `node_modules` folder of the root project or any of its dependencies is somehow replaced with a symbolic link, it could allow Arborist to write package dependencies to any arbitrary location on the file system. Note that symbolic links contained within package artifact contents are filtered out, so another means of creating a `node_modules` symbolic link would have to be employed. 1. A `preinstall` script could replace `node_modules` with a symlink. (This is prevented by using `--ignore-scripts`.) 2. An attacker could supply the target with a git repository, instructing them to run `npm install --ignore-scripts` in the root. This may be successful, because `npm install --ignore-scripts` is typically not capable of making changes outside of the project directory, so it may be deemed safe. This is patched in @npmcli/arborist 2.8.2 which is included in npm v7.20.7 and above. For more information including workarounds please see the referenced GHSA-gmw6-94gg-2rc2.\n\n * CVE-2021-44531: Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js \u003c 12.22.9, \u003c 14.18.3, \u003c 16.13.2, and \u003c 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.\n\n * CVE-2021-44532: Node.js \u003c 12.22.9, \u003c 14.18.3, \u003c 16.13.2, and \u003c 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.\n\n * CVE-2021-44533: Node.js \u003c 12.22.9, \u003c 14.18.3, \u003c 16.13.2, and \u003c 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.\n\n * CVE-2022-0778: The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature. This issue affects OpenSSL versions 1.0.2, 1.1.1 and 3.0. It was addressed in the releases of 1.1.1n and 3.0.2 on the 15th March 2022. Fixed in OpenSSL 3.0.2 (Affected 3.0.0,3.0.1). Fixed in OpenSSL 1.1.1n (Affected 1.1.1-1.1.1m). Fixed in OpenSSL 1.0.2zd (Affected 1.0.2-1.0.2zc).\n\n * CVE-2022-21824: Due to the formatting logic of the \"console.table()\" function it was not safe to allow user controlled input to be passed to the \"properties\" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be \"__proto__\". The prototype pollution has very limited control, in that it only allows an empty string to be assigned to numerical keys of the object prototype.Node.js \u003e= 12.22.9, \u003e= 14.18.3, \u003e= 16.13.2, and \u003e= 17.3.1 use a null protoype for the object these properties are being assigned to.\n\n * CVE-2022-32212: A OS Command Injection vulnerability exists in Node.js versions \u003c14.20.0, \u003c16.20.0, \u003c18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.\n\n * CVE-2022-32213: The llhttp parser \u003cv14.20.1, \u003cv16.17.1 and \u003cv18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).\n\n * CVE-2022-32214: The llhttp parser \u003cv14.20.1, \u003cv16.17.1 and \u003cv18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\n\n * CVE-2022-32215: The llhttp parser \u003cv14.20.1, \u003cv16.17.1 and \u003cv18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).\n\n * CVE-2022-35255: A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.\n\n * CVE-2022-35256: The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-11-14"
},
"Updated": {
"Date": "2022-11-14"
},
"BDUs": [
{
"ID": "BDU:2020-03621",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-285, CWE-295",
"Href": "https://bdu.fstec.ru/vul/2020-03621",
"Impact": "High",
"Public": "20200305"
},
{
"ID": "BDU:2020-04460",
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2020-04460",
"Impact": "High",
"Public": "20200724"
},
{
"ID": "BDU:2020-04461",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-707",
"Href": "https://bdu.fstec.ru/vul/2020-04461",
"Impact": "High",
"Public": "20200603"
},
{
"ID": "BDU:2020-05054",
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2020-05054",
"Impact": "High",
"Public": "20200724"
},
{
"ID": "BDU:2020-05657",
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-444",
"Href": "https://bdu.fstec.ru/vul/2020-05657",
"Impact": "High",
"Public": "20200918"
},
{
"ID": "BDU:2020-05687",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://bdu.fstec.ru/vul/2020-05687",
"Impact": "High",
"Public": "20200918"
},
{
"ID": "BDU:2021-00872",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2021-00872",
"Impact": "Low",
"Public": "20201218"
},
{
"ID": "BDU:2021-00883",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2021-00883",
"Impact": "High",
"Public": "20210106"
},
{
"ID": "BDU:2021-01024",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://bdu.fstec.ru/vul/2021-01024",
"Impact": "High",
"Public": "20201118"
},
{
"ID": "BDU:2021-01025",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://bdu.fstec.ru/vul/2021-01025",
"Impact": "Low",
"Public": "20210106"
},
{
"ID": "BDU:2021-01844",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2021-01844",
"Impact": "Low",
"Public": "20180111"
},
{
"ID": "BDU:2021-01895",
"CVSS": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-350",
"Href": "https://bdu.fstec.ru/vul/2021-01895",
"Impact": "High",
"Public": "20210101"
},
{
"ID": "BDU:2021-01896",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://bdu.fstec.ru/vul/2021-01896",
"Impact": "High",
"Public": "20201125"
},
{
"ID": "BDU:2021-03700",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2021-03700",
"Impact": "High",
"Public": "20210526"
},
{
"ID": "BDU:2021-03742",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-190",
"Href": "https://bdu.fstec.ru/vul/2021-03742",
"Impact": "High",
"Public": "20210216"
},
{
"ID": "BDU:2021-04210",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2021-04210",
"Impact": "Low",
"Public": "20210625"
},
{
"ID": "BDU:2021-04995",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-444",
"Href": "https://bdu.fstec.ru/vul/2021-04995",
"Impact": "Critical",
"Public": "20211014"
},
{
"ID": "BDU:2021-04996",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-444",
"Href": "https://bdu.fstec.ru/vul/2021-04996",
"Impact": "Critical",
"Public": "20211012"
},
{
"ID": "BDU:2022-00115",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"CWE": "CWE-59, CWE-61",
"Href": "https://bdu.fstec.ru/vul/2022-00115",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "BDU:2022-00201",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2022-00201",
"Impact": "High",
"Public": "20210724"
},
{
"ID": "BDU:2022-00226",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2022-00226",
"Impact": "High",
"Public": "20210727"
},
{
"ID": "BDU:2022-00316",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2022-00316",
"Impact": "Critical",
"Public": "20211007"
},
{
"ID": "BDU:2022-00342",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2022-00342",
"Impact": "Low",
"Public": "20210810"
},
{
"ID": "BDU:2022-00758",
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2022-00758",
"Impact": "High",
"Public": "20211231"
},
{
"ID": "BDU:2022-00760",
"CVSS": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-94, CWE-915, CWE-1321",
"Href": "https://bdu.fstec.ru/vul/2022-00760",
"Impact": "Low",
"Public": "20210820"
},
{
"ID": "BDU:2022-01315",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://bdu.fstec.ru/vul/2022-01315",
"Impact": "High",
"Public": "20220315"
},
{
"ID": "BDU:2022-01889",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:C/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2022-01889",
"Impact": "High",
"Public": "20210816"
},
{
"ID": "BDU:2022-01892",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-20",
"Href": "https://bdu.fstec.ru/vul/2022-01892",
"Impact": "Critical",
"Public": "20210816"
},
{
"ID": "BDU:2022-02171",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2022-02171",
"Impact": "Low",
"Public": "20210816"
},
{
"ID": "BDU:2022-02880",
"CVSS": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2022-02880",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "BDU:2022-03022",
"CVSS": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"CWE": "CWE-22, CWE-59",
"Href": "https://bdu.fstec.ru/vul/2022-03022",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "BDU:2022-03042",
"CVSS": "AV:L/AC:M/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N",
"CWE": "CWE-22, CWE-59",
"Href": "https://bdu.fstec.ru/vul/2022-03042",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "BDU:2022-04390",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"CWE": "CWE-444",
"Href": "https://bdu.fstec.ru/vul/2022-04390",
"Impact": "High",
"Public": "20220707"
},
{
"ID": "BDU:2023-00348",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-444",
"Href": "https://bdu.fstec.ru/vul/2023-00348",
"Impact": "Critical",
"Public": "20221205"
}
],
"CVEs": [
{
"ID": "CVE-2020-11080",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-707",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-11080",
"Impact": "High",
"Public": "20200603"
},
{
"ID": "CVE-2020-1971",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1971",
"Impact": "Low",
"Public": "20201208"
},
{
"ID": "CVE-2020-8172",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8172",
"Impact": "High",
"Public": "20200608"
},
{
"ID": "CVE-2020-8174",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-191",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8174",
"Impact": "High",
"Public": "20200724"
},
{
"ID": "CVE-2020-8201",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8201",
"Impact": "High",
"Public": "20200918"
},
{
"ID": "CVE-2020-8251",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8251",
"Impact": "High",
"Public": "20200918"
},
{
"ID": "CVE-2020-8252",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-120",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8252",
"Impact": "High",
"Public": "20200918"
},
{
"ID": "CVE-2020-8265",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8265",
"Impact": "High",
"Public": "20210106"
},
{
"ID": "CVE-2020-8277",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8277",
"Impact": "High",
"Public": "20201119"
},
{
"ID": "CVE-2020-8287",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-8287",
"Impact": "Low",
"Public": "20210106"
},
{
"ID": "CVE-2021-22883",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-772",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22883",
"Impact": "High",
"Public": "20210303"
},
{
"ID": "CVE-2021-22884",
"CVSS": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22884",
"Impact": "High",
"Public": "20210303"
},
{
"ID": "CVE-2021-22918",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22918",
"Impact": "Low",
"Public": "20210712"
},
{
"ID": "CVE-2021-22930",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22930",
"Impact": "Critical",
"Public": "20211007"
},
{
"ID": "CVE-2021-22931",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22931",
"Impact": "Critical",
"Public": "20210816"
},
{
"ID": "CVE-2021-22939",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22939",
"Impact": "Low",
"Public": "20210816"
},
{
"ID": "CVE-2021-22940",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22940",
"Impact": "High",
"Public": "20210816"
},
{
"ID": "CVE-2021-22959",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22959",
"Impact": "Low",
"Public": "20211115"
},
{
"ID": "CVE-2021-22960",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-22960",
"Impact": "Low",
"Public": "20211103"
},
{
"ID": "CVE-2021-23840",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-190",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-23840",
"Impact": "High",
"Public": "20210216"
},
{
"ID": "CVE-2021-32803",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
"CWE": "CWE-59",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-32803",
"Impact": "High",
"Public": "20210803"
},
{
"ID": "CVE-2021-32804",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-32804",
"Impact": "High",
"Public": "20210803"
},
{
"ID": "CVE-2021-3449",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-3449",
"Impact": "Low",
"Public": "20210325"
},
{
"ID": "CVE-2021-3672",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-3672",
"Impact": "Low",
"Public": "20211123"
},
{
"ID": "CVE-2021-37701",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-37701",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "CVE-2021-37712",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-37712",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "CVE-2021-37713",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-37713",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "CVE-2021-39134",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-178",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-39134",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "CVE-2021-39135",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-61",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-39135",
"Impact": "High",
"Public": "20210831"
},
{
"ID": "CVE-2021-44531",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-44531",
"Impact": "High",
"Public": "20220224"
},
{
"ID": "CVE-2021-44532",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-44532",
"Impact": "Low",
"Public": "20220224"
},
{
"ID": "CVE-2021-44533",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-44533",
"Impact": "Low",
"Public": "20220224"
},
{
"ID": "CVE-2022-0778",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-0778",
"Impact": "High",
"Public": "20220315"
},
{
"ID": "CVE-2022-21824",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"CWE": "CWE-1321",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-21824",
"Impact": "High",
"Public": "20220224"
},
{
"ID": "CVE-2022-32212",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-78",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-32212",
"Impact": "High",
"Public": "20220714"
},
{
"ID": "CVE-2022-32213",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-32213",
"Impact": "Low",
"Public": "20220714"
},
{
"ID": "CVE-2022-32214",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-32214",
"Impact": "Low",
"Public": "20220714"
},
{
"ID": "CVE-2022-32215",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-32215",
"Impact": "Low",
"Public": "20220714"
},
{
"ID": "CVE-2022-35255",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-338",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-35255",
"Impact": "Critical",
"Public": "20221205"
},
{
"ID": "CVE-2022-35256",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"CWE": "CWE-444",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-35256",
"Impact": "Low",
"Public": "20221205"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20223073001",
"Comment": "node is earlier than 0:16.17.1-alt0.c9.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20223073002",
"Comment": "node-devel is earlier than 0:16.17.1-alt0.c9.1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20223073003",
"Comment": "node-doc is earlier than 0:16.17.1-alt0.c9.1"
}
]
}
]
}
}
]
}