2024-06-28 13:17:52 +00:00

169 lines
6.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20152137",
"Version": "oval:org.altlinux.errata:def:20152137",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-2137: package `libldb` update to version 1.1.24-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-2137",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-2137",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-01296",
"RefURL": "https://bdu.fstec.ru/vul/2021-01296",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01299",
"RefURL": "https://bdu.fstec.ru/vul/2021-01299",
"Source": "BDU"
},
{
"RefID": "CVE-2015-3223",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-3223",
"Source": "CVE"
},
{
"RefID": "CVE-2015-5330",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-5330",
"Source": "CVE"
}
],
"Description": "This update upgrades libldb to version 1.1.24-alt1. \nSecurity Fix(es):\n\n * BDU:2021-01296: Уязвимость библиотеки libldb пакета программ сетевого взаимодействия Samba, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным\n\n * BDU:2021-01299: Уязвимость функции ldb_wildcard_compare пакета программ сетевого взаимодействия Samba, связанная с ошибкой в обработке чисел, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2015-3223: The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles certain zero values, which allows remote attackers to cause a denial of service (infinite loop) via crafted packets.\n\n * CVE-2015-5330: ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, which allows remote attackers to obtain sensitive information from daemon heap memory by sending crafted packets and then reading (1) an error message or (2) a database value.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-12-17"
},
"Updated": {
"Date": "2015-12-17"
},
"BDUs": [
{
"ID": "BDU:2021-01296",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2021-01296",
"Impact": "High",
"Public": "20151229"
},
{
"ID": "BDU:2021-01299",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"CWE": "CWE-189",
"Href": "https://bdu.fstec.ru/vul/2021-01299",
"Impact": "Low",
"Public": "20151229"
}
],
"CVEs": [
{
"ID": "CVE-2015-3223",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"CWE": "CWE-189",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-3223",
"Impact": "Low",
"Public": "20151229"
},
{
"ID": "CVE-2015-5330",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-5330",
"Impact": "High",
"Public": "20151229"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20152137001",
"Comment": "ldb-tools is earlier than 0:1.1.24-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20152137002",
"Comment": "libldb is earlier than 0:1.1.24-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20152137003",
"Comment": "libldb-devel is earlier than 0:1.1.24-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20152137004",
"Comment": "python-module-pyldb is earlier than 0:1.1.24-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20152137005",
"Comment": "python-module-pyldb-devel is earlier than 0:1.1.24-alt1"
}
]
}
]
}
}
]
}