vuln-list-alt/oval/p10/ALT-PU-2020-1909/definitions.json
2024-06-28 13:17:52 +00:00

161 lines
6.9 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20201909",
"Version": "oval:org.altlinux.errata:def:20201909",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-1909: package `squid` update to version 4.11-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-1909",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1909",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-01723",
"RefURL": "https://bdu.fstec.ru/vul/2021-01723",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01747",
"RefURL": "https://bdu.fstec.ru/vul/2021-01747",
"Source": "BDU"
},
{
"RefID": "CVE-2019-12519",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-12519",
"Source": "CVE"
},
{
"RefID": "CVE-2020-11945",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-11945",
"Source": "CVE"
}
],
"Description": "This update upgrades squid to version 4.11-alt1. \nSecurity Fix(es):\n\n * BDU:2021-01723: Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2021-01747: Уязвимость функции ESIExpression:: Evaluate прокси-сервера Squid, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2019-12519: An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.\n\n * CVE-2020-11945: An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-05-01"
},
"Updated": {
"Date": "2020-05-01"
},
"BDUs": [
{
"ID": "BDU:2021-01723",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-190",
"Href": "https://bdu.fstec.ru/vul/2021-01723",
"Impact": "Critical",
"Public": "20200423"
},
{
"ID": "BDU:2021-01747",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2021-01747",
"Impact": "Critical",
"Public": "20200415"
}
],
"CVEs": [
{
"ID": "CVE-2019-12519",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-12519",
"Impact": "Critical",
"Public": "20200415"
},
{
"ID": "CVE-2020-11945",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-190",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-11945",
"Impact": "Critical",
"Public": "20200423"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20201909001",
"Comment": "squid is earlier than 0:4.11-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201909002",
"Comment": "squid-doc is earlier than 0:4.11-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201909003",
"Comment": "squid-helpers is earlier than 0:4.11-alt1"
}
]
}
]
}
}
]
}