vuln-list-alt/oval/c9f2/ALT-PU-2015-1053/definitions.json
2024-07-06 03:04:52 +00:00

150 lines
5.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20151053",
"Version": "oval:org.altlinux.errata:def:20151053",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-1053: package `openvpn` update to version 2.3.6-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-1053",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-1053",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-09682",
"RefURL": "https://bdu.fstec.ru/vul/2015-09682",
"Source": "BDU"
},
{
"RefID": "BDU:2015-09796",
"RefURL": "https://bdu.fstec.ru/vul/2015-09796",
"Source": "BDU"
},
{
"RefID": "CVE-2013-2061",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2013-2061",
"Source": "CVE"
},
{
"RefID": "CVE-2014-8104",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-8104",
"Source": "CVE"
}
],
"Description": "This update upgrades openvpn to version 2.3.6-alt1. \nSecurity Fix(es):\n\n * BDU:2015-09682: Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации\n\n * BDU:2015-09796: Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации\n\n * CVE-2013-2061: The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.\n\n * CVE-2014-8104: OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.\n\n * #28071: openvpn: Необходимо обеспечить совместимость службы с systemd\n\n * #30529: CVE-2014-8104 Critical denial of service vulnerability in OpenVPN servers\n\n * #30614: pkcs11 support",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-01-17"
},
"Updated": {
"Date": "2015-01-17"
},
"BDUs": [
{
"ID": "BDU:2015-09682",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2015-09682",
"Impact": "Low",
"Public": "20131120"
},
{
"ID": "BDU:2015-09796",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:N/A:C",
"CWE": "CWE-399",
"Href": "https://bdu.fstec.ru/vul/2015-09796",
"Impact": "Low",
"Public": "20141226"
}
],
"CVEs": [
{
"ID": "CVE-2013-2061",
"CVSS": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2013-2061",
"Impact": "Low",
"Public": "20131118"
},
{
"ID": "CVE-2014-8104",
"CVSS": "AV:N/AC:L/Au:S/C:N/I:N/A:C",
"CWE": "CWE-399",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-8104",
"Impact": "Low",
"Public": "20141203"
}
],
"Bugzilla": [
{
"ID": "28071",
"Href": "https://bugzilla.altlinux.org/28071",
"Data": "openvpn: Необходимо обеспечить совместимость службы с systemd"
},
{
"ID": "30529",
"Href": "https://bugzilla.altlinux.org/30529",
"Data": "CVE-2014-8104 Critical denial of service vulnerability in OpenVPN servers"
},
{
"ID": "30614",
"Href": "https://bugzilla.altlinux.org/30614",
"Data": "pkcs11 support"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20151053001",
"Comment": "openvpn is earlier than 0:2.3.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151053002",
"Comment": "openvpn-docs is earlier than 0:2.3.6-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20151053003",
"Comment": "openvpn-plugins is earlier than 0:2.3.6-alt1"
}
]
}
]
}
}
]
}