2024-06-28 13:17:52 +00:00

110 lines
3.5 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172653",
"Version": "oval:org.altlinux.errata:def:20172653",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2653: package `novnc` update to version 0.6.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2653",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2653",
"Source": "ALTPU"
},
{
"RefID": "CVE-2017-18635",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-18635",
"Source": "CVE"
}
],
"Description": "This update upgrades novnc to version 0.6.2-alt1. \nSecurity Fix(es):\n\n * CVE-2017-18635: An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-11-16"
},
"Updated": {
"Date": "2017-11-16"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2017-18635",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-18635",
"Impact": "Low",
"Public": "20190925"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172653001",
"Comment": "novnc is earlier than 0:0.6.2-alt1"
}
]
}
]
}
}
]
}