vuln-list-alt/oval/c9f2/ALT-PU-2019-1411/definitions.json
2024-06-28 13:17:52 +00:00

173 lines
7.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191411",
"Version": "oval:org.altlinux.errata:def:20191411",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1411: package `wireshark` update to version 2.6.7-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1411",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1411",
"Source": "ALTPU"
},
{
"RefID": "BDU:2019-01351",
"RefURL": "https://bdu.fstec.ru/vul/2019-01351",
"Source": "BDU"
},
{
"RefID": "BDU:2019-01573",
"RefURL": "https://bdu.fstec.ru/vul/2019-01573",
"Source": "BDU"
},
{
"RefID": "BDU:2019-01574",
"RefURL": "https://bdu.fstec.ru/vul/2019-01574",
"Source": "BDU"
},
{
"RefID": "CVE-2019-9208",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-9208",
"Source": "CVE"
},
{
"RefID": "CVE-2019-9209",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-9209",
"Source": "CVE"
},
{
"RefID": "CVE-2019-9214",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-9214",
"Source": "CVE"
}
],
"Description": "This update upgrades wireshark to version 2.6.7-alt1. \nSecurity Fix(es):\n\n * BDU:2019-01351: Уязвимость диссектора RPCAP (epan/dissectors/packet-rpcap.c) анализатора трафика компьютерных сетей Wireshark, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2019-01573: Уязвимость компонента TCAP диссектора анализатора трафика компьютерных сетей Wireshark, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2019-01574: Уязвимость компонента ASN.1 BER диссектора анализатора трафика компьютерных сетей Wireshark, связанная с выходом операции за границы памяти, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-9208: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could crash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding NULL pointer dereferences.\n\n * CVE-2019-9209: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.\n\n * CVE-2019-9214: In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the RPCAP dissector could crash. This was addressed in epan/dissectors/packet-rpcap.c by avoiding an attempted dereference of a NULL conversation.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-03-13"
},
"Updated": {
"Date": "2019-03-13"
},
"BDUs": [
{
"ID": "BDU:2019-01351",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2019-01351",
"Impact": "High",
"Public": "20190227"
},
{
"ID": "BDU:2019-01573",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2019-01573",
"Impact": "High",
"Public": "20190129"
},
{
"ID": "BDU:2019-01574",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2019-01574",
"Impact": "High",
"Public": "20190125"
}
],
"CVEs": [
{
"ID": "CVE-2019-9208",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-9208",
"Impact": "High",
"Public": "20190228"
},
{
"ID": "CVE-2019-9209",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-9209",
"Impact": "Low",
"Public": "20190228"
},
{
"ID": "CVE-2019-9214",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-9214",
"Impact": "High",
"Public": "20190228"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191411001",
"Comment": "tshark is earlier than 0:2.6.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191411002",
"Comment": "wireshark-base is earlier than 0:2.6.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191411003",
"Comment": "wireshark-devel is earlier than 0:2.6.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191411004",
"Comment": "wireshark-doc is earlier than 0:2.6.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191411005",
"Comment": "wireshark-qt5 is earlier than 0:2.6.7-alt1"
}
]
}
]
}
}
]
}