vuln-list-alt/oval/c9f2/ALT-PU-2019-2824/definitions.json
2024-06-28 13:17:52 +00:00

121 lines
4.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20192824",
"Version": "oval:org.altlinux.errata:def:20192824",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-2824: package `unbound` update to version 1.9.4-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-2824",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-2824",
"Source": "ALTPU"
},
{
"RefID": "BDU:2019-04712",
"RefURL": "https://bdu.fstec.ru/vul/2019-04712",
"Source": "BDU"
},
{
"RefID": "CVE-2019-16866",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-16866",
"Source": "CVE"
}
],
"Description": "This update upgrades unbound to version 1.9.4-alt1. \nSecurity Fix(es):\n\n * BDU:2019-04712: Уязвимость DNS-сервера Unbound, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-16866: Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-10-04"
},
"Updated": {
"Date": "2019-10-04"
},
"BDUs": [
{
"ID": "BDU:2019-04712",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2019-04712",
"Impact": "High",
"Public": "20191003"
}
],
"CVEs": [
{
"ID": "CVE-2019-16866",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-755",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-16866",
"Impact": "High",
"Public": "20191003"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20192824001",
"Comment": "libunbound is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192824002",
"Comment": "libunbound-devel is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192824003",
"Comment": "libunbound-devel-static is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192824004",
"Comment": "python-module-unbound is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192824005",
"Comment": "unbound is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192824006",
"Comment": "unbound-control is earlier than 0:1.9.4-alt1"
}
]
}
]
}
}
]
}