2024-06-28 13:17:52 +00:00

188 lines
8.0 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20151346",
"Version": "oval:org.altlinux.errata:def:20151346",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-1346: package `freerdp` update to version 1.1.0-alt1.beta1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-1346",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-1346",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-02923",
"RefURL": "https://bdu.fstec.ru/vul/2020-02923",
"Source": "BDU"
},
{
"RefID": "CVE-2013-4118",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2013-4118",
"Source": "CVE"
},
{
"RefID": "CVE-2013-4119",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2013-4119",
"Source": "CVE"
},
{
"RefID": "CVE-2014-0250",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-0250",
"Source": "CVE"
},
{
"RefID": "CVE-2014-0791",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-0791",
"Source": "CVE"
},
{
"RefID": "CVE-2019-17177",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-17177",
"Source": "CVE"
},
{
"RefID": "CVE-2019-17178",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-17178",
"Source": "CVE"
}
],
"Description": "This update upgrades freerdp to version 1.1.0-alt1.beta1. \nSecurity Fix(es):\n\n * BDU:2020-02923: Уязвимость реализации протокола удалённого рабочего стола FreeRDP, связанная с неосвобождением ресурса после истечения действительного срока его эксплуатирования, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2013-4118: FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.\n\n * CVE-2013-4119: FreeRDP before 1.1.0-beta+2013071101 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by disconnecting before authentication has finished.\n\n * CVE-2014-0250: Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.\n\n * CVE-2014-0791: Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet.\n\n * CVE-2019-17177: libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.\n\n * CVE-2019-17178: HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other products, has a memory leak because a supplied realloc pointer (i.e., the first argument to realloc) is also used for a realloc return value.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-04-01"
},
"Updated": {
"Date": "2015-04-01"
},
"BDUs": [
{
"ID": "BDU:2020-02923",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CWE": "CWE-772",
"Href": "https://bdu.fstec.ru/vul/2020-02923",
"Impact": "Low",
"Public": "20191004"
}
],
"CVEs": [
{
"ID": "CVE-2013-4118",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2013-4118",
"Impact": "High",
"Public": "20161003"
},
{
"ID": "CVE-2013-4119",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2013-4119",
"Impact": "High",
"Public": "20161003"
},
{
"ID": "CVE-2014-0250",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-0250",
"Impact": "High",
"Public": "20141116"
},
{
"ID": "CVE-2014-0791",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-0791",
"Impact": "Low",
"Public": "20140103"
},
{
"ID": "CVE-2019-17177",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-401",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-17177",
"Impact": "High",
"Public": "20191004"
},
{
"ID": "CVE-2019-17178",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-252",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-17178",
"Impact": "High",
"Public": "20191004"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20151346001",
"Comment": "dfreerdp is earlier than 0:1.1.0-alt1.beta1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151346002",
"Comment": "freerdp is earlier than 0:1.1.0-alt1.beta1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151346003",
"Comment": "freerdp-plugins-standard is earlier than 0:1.1.0-alt1.beta1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151346004",
"Comment": "libfreerdp is earlier than 0:1.1.0-alt1.beta1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151346005",
"Comment": "libfreerdp-devel is earlier than 0:1.1.0-alt1.beta1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151346006",
"Comment": "xfreerdp is earlier than 0:1.1.0-alt1.beta1"
}
]
}
]
}
}
]
}