2024-06-28 13:17:52 +00:00

201 lines
7.9 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20203218",
"Version": "oval:org.altlinux.errata:def:20203218",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-3218: package `libxml2` update to version 2.9.10-alt4",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-3218",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-3218",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03623",
"RefURL": "https://bdu.fstec.ru/vul/2020-03623",
"Source": "BDU"
},
{
"RefID": "BDU:2020-04514",
"RefURL": "https://bdu.fstec.ru/vul/2020-04514",
"Source": "BDU"
},
{
"RefID": "BDU:2021-03429",
"RefURL": "https://bdu.fstec.ru/vul/2021-03429",
"Source": "BDU"
},
{
"RefID": "CVE-2019-20388",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-20388",
"Source": "CVE"
},
{
"RefID": "CVE-2020-24977",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-24977",
"Source": "CVE"
},
{
"RefID": "CVE-2020-7595",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-7595",
"Source": "CVE"
}
],
"Description": "This update upgrades libxml2 to version 2.9.10-alt4. \nSecurity Fix(es):\n\n * BDU:2020-03623: Уязвимость функций xmlStringLenDecodeEntities библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-04514: Уязвимость компонента xmlschemas.c библиотеки libxml2, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-03429: Уязвимость функции xmlEncodeEntitiesInternal компонента libxml2/entities.c библиотеки Libxml2, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании\n\n * CVE-2019-20388: xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.\n\n * CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.\n\n * CVE-2020-7595: xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-11-06"
},
"Updated": {
"Date": "2020-11-06"
},
"BDUs": [
{
"ID": "BDU:2020-03623",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"CWE": "CWE-835",
"Href": "https://bdu.fstec.ru/vul/2020-03623",
"Impact": "Low",
"Public": "20191212"
},
{
"ID": "BDU:2020-04514",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-404",
"Href": "https://bdu.fstec.ru/vul/2020-04514",
"Impact": "High",
"Public": "20190820"
},
{
"ID": "BDU:2021-03429",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2021-03429",
"Impact": "Low",
"Public": "20200804"
}
],
"CVEs": [
{
"ID": "CVE-2019-20388",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-401",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-20388",
"Impact": "High",
"Public": "20200121"
},
{
"ID": "CVE-2020-24977",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-24977",
"Impact": "Low",
"Public": "20200904"
},
{
"ID": "CVE-2020-7595",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-7595",
"Impact": "High",
"Public": "20200121"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20203218001",
"Comment": "libxml2 is earlier than 1:2.9.10-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203218002",
"Comment": "libxml2-devel is earlier than 1:2.9.10-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203218003",
"Comment": "libxml2-doc is earlier than 1:2.9.10-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203218004",
"Comment": "python-module-libxml2 is earlier than 1:2.9.10-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203218005",
"Comment": "python3-module-libxml2 is earlier than 1:2.9.10-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203218006",
"Comment": "xml-utils is earlier than 1:2.9.10-alt4"
}
]
}
]
}
}
]
}