293 lines
13 KiB
JSON
293 lines
13 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20191565",
|
||
"Version": "oval:org.altlinux.errata:def:20191565",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2019-1565: package `python` update to version 2.7.16-alt1",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c9f2"
|
||
],
|
||
"Products": [
|
||
"ALT SPWorkstation",
|
||
"ALT SPServer"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2019-1565",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1565",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2018-01554",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2018-01554",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2019-00437",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2019-00437",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2019-02457",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2019-02457",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2018-1000802",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000802",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2018-14647",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-14647",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2019-5010",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-5010",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades python to version 2.7.16-alt1. \nSecurity Fix(es):\n\n * BDU:2018-01554: Уязвимость пакета программ Python, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2019-00437: Уязвимость функции make_archive модуля shutil интерпретатора языка программирования Python (CPython), позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к информации\n\n * BDU:2019-02457: Уязвимость процедуры синтаксического анализа сертификата интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2018-1000802: Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.\n\n * CVE-2018-14647: Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.\n\n * CVE-2019-5010: An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger this vulnerability.",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "Critical",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2019-04-01"
|
||
},
|
||
"Updated": {
|
||
"Date": "2019-04-01"
|
||
},
|
||
"BDUs": [
|
||
{
|
||
"ID": "BDU:2018-01554",
|
||
"CVSS": "AV:A/AC:M/Au:S/C:N/I:N/A:P",
|
||
"CVSS3": "AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
|
||
"CWE": "CWE-404",
|
||
"Href": "https://bdu.fstec.ru/vul/2018-01554",
|
||
"Impact": "Low",
|
||
"Public": "20180910"
|
||
},
|
||
{
|
||
"ID": "BDU:2019-00437",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-77",
|
||
"Href": "https://bdu.fstec.ru/vul/2019-00437",
|
||
"Impact": "Critical",
|
||
"Public": "20180918"
|
||
},
|
||
{
|
||
"ID": "BDU:2019-02457",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"CWE": "CWE-476",
|
||
"Href": "https://bdu.fstec.ru/vul/2019-02457",
|
||
"Impact": "High",
|
||
"Public": "20190115"
|
||
}
|
||
],
|
||
"CVEs": [
|
||
{
|
||
"ID": "CVE-2018-1000802",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-77",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000802",
|
||
"Impact": "Critical",
|
||
"Public": "20180918"
|
||
},
|
||
{
|
||
"ID": "CVE-2018-14647",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"CWE": "CWE-909",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-14647",
|
||
"Impact": "High",
|
||
"Public": "20180925"
|
||
},
|
||
{
|
||
"ID": "CVE-2019-5010",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"CWE": "CWE-476",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-5010",
|
||
"Impact": "High",
|
||
"Public": "20191031"
|
||
}
|
||
],
|
||
"AffectedCPEs": {
|
||
"CPEs": [
|
||
"cpe:/o:alt:spworkstation:8.4",
|
||
"cpe:/o:alt:spserver:8.4"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565001",
|
||
"Comment": "libpython is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565002",
|
||
"Comment": "python is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565003",
|
||
"Comment": "python-base is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565004",
|
||
"Comment": "python-dev is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565005",
|
||
"Comment": "python-devel-static is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565006",
|
||
"Comment": "python-modules is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565007",
|
||
"Comment": "python-modules-bsddb is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565008",
|
||
"Comment": "python-modules-compiler is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565009",
|
||
"Comment": "python-modules-ctypes is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565010",
|
||
"Comment": "python-modules-curses is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565011",
|
||
"Comment": "python-modules-distutils is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565012",
|
||
"Comment": "python-modules-email is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565013",
|
||
"Comment": "python-modules-encodings is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565014",
|
||
"Comment": "python-modules-ensurepip is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565015",
|
||
"Comment": "python-modules-hotshot is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565016",
|
||
"Comment": "python-modules-json is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565017",
|
||
"Comment": "python-modules-logging is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565018",
|
||
"Comment": "python-modules-multiprocessing is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565019",
|
||
"Comment": "python-modules-nis is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565020",
|
||
"Comment": "python-modules-sqlite3 is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565021",
|
||
"Comment": "python-modules-tkinter is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565022",
|
||
"Comment": "python-modules-unittest is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565023",
|
||
"Comment": "python-modules-wsgiref is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565024",
|
||
"Comment": "python-modules-xml is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565025",
|
||
"Comment": "python-relaxed is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565026",
|
||
"Comment": "python-strict is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565027",
|
||
"Comment": "python-test is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565028",
|
||
"Comment": "python-tools-2to3 is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565029",
|
||
"Comment": "python-tools-i18n is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565030",
|
||
"Comment": "python-tools-idle is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565031",
|
||
"Comment": "python-tools-pynche is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565032",
|
||
"Comment": "python-tools-scripts is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565033",
|
||
"Comment": "python-tools-smtpd is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565034",
|
||
"Comment": "python-tools-webchecker is earlier than 0:2.7.16-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191565035",
|
||
"Comment": "python-user-scripts is earlier than 0:2.7.16-alt1"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |