2024-06-28 13:17:52 +00:00

138 lines
5.3 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172368",
"Version": "oval:org.altlinux.errata:def:20172368",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2368: package `newsbeuter` update to version 2.9-alt3",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2368",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2368",
"Source": "ALTPU"
},
{
"RefID": "BDU:2017-02033",
"RefURL": "https://bdu.fstec.ru/vul/2017-02033",
"Source": "BDU"
},
{
"RefID": "CVE-2017-12904",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-12904",
"Source": "CVE"
},
{
"RefID": "CVE-2017-14500",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-14500",
"Source": "CVE"
}
],
"Description": "This update upgrades newsbeuter to version 2.9-alt3. \nSecurity Fix(es):\n\n * BDU:2017-02033: Уязвимость функции установки закладки консольной программы Newsbeuter версии от 0.7 до 2.9 операционной системы Debian GNU/Linux, позволяющая нарушителю внедрить код\n\n * CVE-2017-12904: Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.\n\n * CVE-2017-14500: Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-10-03"
},
"Updated": {
"Date": "2017-10-03"
},
"BDUs": [
{
"ID": "BDU:2017-02033",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CWE": "CWE-943",
"Href": "https://bdu.fstec.ru/vul/2017-02033",
"Impact": "Critical",
"Public": "20170818"
}
],
"CVEs": [
{
"ID": "CVE-2017-12904",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-943",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-12904",
"Impact": "High",
"Public": "20170823"
},
{
"ID": "CVE-2017-14500",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-78",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-14500",
"Impact": "High",
"Public": "20170917"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172368001",
"Comment": "newsbeuter is earlier than 0:2.9-alt3"
}
]
}
]
}
}
]
}