178 lines
7.8 KiB
JSON
178 lines
7.8 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20231734",
|
||
"Version": "oval:org.altlinux.errata:def:20231734",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2023-1734: package `golang` update to version 1.19.9-alt1",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c10f1"
|
||
],
|
||
"Products": [
|
||
"ALT SP Workstation",
|
||
"ALT SP Server"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2023-1734",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-1734",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03470",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03470",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03471",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03471",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2023-03472",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2023-03472",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-24539",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-24539",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-24540",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-24540",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2023-29400",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-29400",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades golang to version 1.19.9-alt1. \nSecurity Fix(es):\n\n * BDU:2023-03470: Уязвимость языка программирования Go, связанная с ошибками при обработке специальных символов \u0026quot;\u0026lt;\u0026gt;\u0026quot; в контексте CSS, позволяющая нарушителю выполнить произвольный код\n\n * BDU:2023-03471: Уязвимость языка программирования Go, связанная с ошибками при обработке пробельных символов в контексте JavaScript, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации\n\n * BDU:2023-03472: Уязвимость языка программирования Go, существующая из-за непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю внедрить произвольные атрибуты в теги HTML\n\n * CVE-2023-24539: Angle brackets (\u003c\u003e) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.\n\n * CVE-2023-24540: Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set \"\\t\\n\\f\\r\\u0020\\u2028\\u2029\" in JavaScript contexts that also contain actions may not be properly sanitized during execution.\n\n * CVE-2023-29400: Templates containing actions in unquoted HTML attributes (e.g. \"attr={{.}}\") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "Critical",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2023-05-03"
|
||
},
|
||
"Updated": {
|
||
"Date": "2023-05-03"
|
||
},
|
||
"BDUs": [
|
||
{
|
||
"ID": "BDU:2023-03470",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
|
||
"CWE": "CWE-74",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03470",
|
||
"Impact": "High",
|
||
"Public": "20230511"
|
||
},
|
||
{
|
||
"ID": "BDU:2023-03471",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-74",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03471",
|
||
"Impact": "Critical",
|
||
"Public": "20230511"
|
||
},
|
||
{
|
||
"ID": "BDU:2023-03472",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
|
||
"CWE": "CWE-74",
|
||
"Href": "https://bdu.fstec.ru/vul/2023-03472",
|
||
"Impact": "High",
|
||
"Public": "20230511"
|
||
}
|
||
],
|
||
"CVEs": [
|
||
{
|
||
"ID": "CVE-2023-24539",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
|
||
"CWE": "CWE-74",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-24539",
|
||
"Impact": "High",
|
||
"Public": "20230511"
|
||
},
|
||
{
|
||
"ID": "CVE-2023-24540",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "NVD-CWE-noinfo",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-24540",
|
||
"Impact": "Critical",
|
||
"Public": "20230511"
|
||
},
|
||
{
|
||
"ID": "CVE-2023-29400",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
|
||
"CWE": "CWE-74",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-29400",
|
||
"Impact": "High",
|
||
"Public": "20230511"
|
||
}
|
||
],
|
||
"AffectedCPEs": {
|
||
"CPEs": [
|
||
"cpe:/o:alt:spworkstation:10",
|
||
"cpe:/o:alt:spserver:10"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:4001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734001",
|
||
"Comment": "golang is earlier than 0:1.19.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734002",
|
||
"Comment": "golang-docs is earlier than 0:1.19.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734003",
|
||
"Comment": "golang-gdb is earlier than 0:1.19.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734004",
|
||
"Comment": "golang-misc is earlier than 0:1.19.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734005",
|
||
"Comment": "golang-shared is earlier than 0:1.19.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734006",
|
||
"Comment": "golang-src is earlier than 0:1.19.9-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20231734007",
|
||
"Comment": "golang-tests is earlier than 0:1.19.9-alt1"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |