2024-06-28 13:17:52 +00:00

133 lines
4.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191212",
"Version": "oval:org.altlinux.errata:def:20191212",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1212: package `libidn2` update to version 2.1.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1212",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1212",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01957",
"RefURL": "https://bdu.fstec.ru/vul/2020-01957",
"Source": "BDU"
},
{
"RefID": "CVE-2019-18224",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-18224",
"Source": "CVE"
}
],
"Description": "This update upgrades libidn2 to version 2.1.1-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01957: Уязвимость функции idn2_to_ascii_4i() библиотеке GNU для интернационализованных доменных имён (IDN) libidn2, связанная с записью за границами буфера, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2019-18224: idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-02-12"
},
"Updated": {
"Date": "2019-02-12"
},
"BDUs": [
{
"ID": "BDU:2020-01957",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2020-01957",
"Impact": "Critical",
"Public": "20191021"
}
],
"CVEs": [
{
"ID": "CVE-2019-18224",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-18224",
"Impact": "Critical",
"Public": "20191021"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191212001",
"Comment": "idn2 is earlier than 0:2.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191212002",
"Comment": "libidn2 is earlier than 0:2.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191212003",
"Comment": "libidn2-devel is earlier than 0:2.1.1-alt1"
}
]
}
]
}
}
]
}