vuln-list-alt/oval/c9f2/ALT-PU-2019-1042/definitions.json
2024-06-28 13:17:52 +00:00

164 lines
6.5 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191042",
"Version": "oval:org.altlinux.errata:def:20191042",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1042: package `adobe-flash-player-ppapi` update to version 32-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1042",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1042",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-01535",
"RefURL": "https://bdu.fstec.ru/vul/2018-01535",
"Source": "BDU"
},
{
"RefID": "BDU:2019-04832",
"RefURL": "https://bdu.fstec.ru/vul/2019-04832",
"Source": "BDU"
},
{
"RefID": "CVE-2018-15978",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15978",
"Source": "CVE"
},
{
"RefID": "CVE-2018-15981",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15981",
"Source": "CVE"
},
{
"RefID": "CVE-2018-15982",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15982",
"Source": "CVE"
},
{
"RefID": "CVE-2018-15983",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-15983",
"Source": "CVE"
}
],
"Description": "This update upgrades adobe-flash-player-ppapi to version 32-alt1. \nSecurity Fix(es):\n\n * BDU:2018-01535: Уязвимость программной платформы Flash Player, связанная с ошибками преобразования типов данных, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2019-04832: Уязвимость программной платформы Flash Player, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2018-15978: Flash Player versions 31.0.0.122 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.\n\n * CVE-2018-15981: Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.\n\n * CVE-2018-15982: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.\n\n * CVE-2018-15983: Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.\n\n * #34555: chromium ругается на старый flash",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-01-15"
},
"Updated": {
"Date": "2019-01-15"
},
"BDUs": [
{
"ID": "BDU:2018-01535",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-843",
"Href": "https://bdu.fstec.ru/vul/2018-01535",
"Impact": "High",
"Public": "20181120"
},
{
"ID": "BDU:2019-04832",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2019-04832",
"Impact": "Critical",
"Public": "20181205"
}
],
"CVEs": [
{
"ID": "CVE-2018-15978",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15978",
"Impact": "High",
"Public": "20181129"
},
{
"ID": "CVE-2018-15981",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-704",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15981",
"Impact": "Critical",
"Public": "20181129"
},
{
"ID": "CVE-2018-15982",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15982",
"Impact": "Critical",
"Public": "20190118"
},
{
"ID": "CVE-2018-15983",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-426",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-15983",
"Impact": "High",
"Public": "20190118"
}
],
"Bugzilla": [
{
"ID": "34555",
"Href": "https://bugzilla.altlinux.org/34555",
"Data": "chromium ругается на старый flash"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191042001",
"Comment": "ppapi-plugin-adobe-flash is earlier than 3:32.0.0.114-alt1"
}
]
}
]
}
}
]
}