2024-04-16 14:26:14 +00:00

215 lines
8.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20231241",
"Version": "oval:org.altlinux.errata:def:20231241",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2023-1241: package `LibreOffice` update to version 7.4.2.3-alt4",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2023-1241",
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-1241",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-06246",
"RefURL": "https://bdu.fstec.ru/vul/2022-06246",
"Source": "BDU"
},
{
"RefID": "CVE-2022-3140",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-3140",
"Source": "CVE"
}
],
"Description": "This update upgrades LibreOffice to version 7.4.2.3-alt4. \nSecurity Fix(es):\n\n * BDU:2022-06246: Уязвимость реализации схемы vnd.libreoffice.command пакета офисных программ LibreOffice, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2022-3140: LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.1; 7.3 versions prior to 7.3.6.\n\n * #44176: Не совпадения названий бинарников и вызовов в файлах .desktop",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2023-02-14"
},
"Updated": {
"Date": "2023-02-14"
},
"BDUs": [
{
"ID": "BDU:2022-06246",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-77",
"Href": "https://bdu.fstec.ru/vul/2022-06246",
"Impact": "Critical",
"Public": "20221011"
}
],
"CVEs": [
{
"ID": "CVE-2022-3140",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
"CWE": "CWE-88",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-3140",
"Impact": "Low",
"Public": "20221011"
}
],
"Bugzilla": [
{
"ID": "44176",
"Href": "https://bugzilla.altlinux.org/44176",
"Data": "Не совпадения названий бинарников и вызовов в файлах .desktop"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20231241001",
"Comment": "LibreOffice is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241002",
"Comment": "LibreOffice-common is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241003",
"Comment": "LibreOffice-extensions is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241004",
"Comment": "LibreOffice-gtk3 is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241005",
"Comment": "LibreOffice-gtk3-kde5 is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241006",
"Comment": "LibreOffice-integrated is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241007",
"Comment": "LibreOffice-kde5 is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241008",
"Comment": "LibreOffice-langpack-be is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241009",
"Comment": "LibreOffice-langpack-de is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241010",
"Comment": "LibreOffice-langpack-en_US is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241011",
"Comment": "LibreOffice-langpack-es is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241012",
"Comment": "LibreOffice-langpack-fr is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241013",
"Comment": "LibreOffice-langpack-kk is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241014",
"Comment": "LibreOffice-langpack-pt_BR is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241015",
"Comment": "LibreOffice-langpack-ru is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241016",
"Comment": "LibreOffice-langpack-tt is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241017",
"Comment": "LibreOffice-langpack-uk is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241018",
"Comment": "LibreOffice-postgresql is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241019",
"Comment": "LibreOffice-qt5 is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241020",
"Comment": "LibreOffice-sdk is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241021",
"Comment": "libreofficekit is earlier than 0:7.4.2.3-alt4"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231241022",
"Comment": "libreofficekit-devel is earlier than 0:7.4.2.3-alt4"
}
]
}
]
}
}
]
}