145 lines
5.7 KiB
JSON
145 lines
5.7 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20191771",
|
||
"Version": "oval:org.altlinux.errata:def:20191771",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2019-1771: package `polkit` update to version 0.116-alt1",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c9f2"
|
||
],
|
||
"Products": [
|
||
"ALT SPWorkstation",
|
||
"ALT SPServer"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2019-1771",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1771",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2019-00885",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2019-00885",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2019-01338",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2019-01338",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2018-19788",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-19788",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2019-6133",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-6133",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades polkit to version 0.116-alt1. \nSecurity Fix(es):\n\n * BDU:2019-00885: Уязвимость программной платформы для управления административными политиками и привилегиями Policykit, связанная с ошибками при обработке больших значений идентификаторов пользователей, позволяющая нарушителю обойти процедуру аутентификации\n\n * BDU:2019-01338: Уязвимость библиотеки Polkit операционных систем Linux, позволяющая нарушителю выполнить произвольные команды\n\n * CVE-2018-19788: A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.\n\n * CVE-2019-6133: In PolicyKit (aka polkit) 0.115, the \"start time\" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "High",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2019-05-06"
|
||
},
|
||
"Updated": {
|
||
"Date": "2019-05-06"
|
||
},
|
||
"BDUs": [
|
||
{
|
||
"ID": "BDU:2019-00885",
|
||
"CVSS": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
|
||
"CVSS3": "AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-287",
|
||
"Href": "https://bdu.fstec.ru/vul/2019-00885",
|
||
"Impact": "High",
|
||
"Public": "20181202"
|
||
},
|
||
{
|
||
"ID": "BDU:2019-01338",
|
||
"CVSS": "AV:L/AC:M/Au:S/C:C/I:C/A:C",
|
||
"CVSS3": "AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-284, CWE-362",
|
||
"Href": "https://bdu.fstec.ru/vul/2019-01338",
|
||
"Impact": "Low",
|
||
"Public": "20190108"
|
||
}
|
||
],
|
||
"CVEs": [
|
||
{
|
||
"ID": "CVE-2018-19788",
|
||
"CVSS": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
|
||
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-20",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-19788",
|
||
"Impact": "High",
|
||
"Public": "20181203"
|
||
},
|
||
{
|
||
"ID": "CVE-2019-6133",
|
||
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
|
||
"CVSS3": "CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
|
||
"CWE": "CWE-362",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-6133",
|
||
"Impact": "Low",
|
||
"Public": "20190111"
|
||
}
|
||
],
|
||
"AffectedCPEs": {
|
||
"CPEs": [
|
||
"cpe:/o:alt:spworkstation:8.4",
|
||
"cpe:/o:alt:spserver:8.4"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191771001",
|
||
"Comment": "libpolkit is earlier than 0:0.116-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191771002",
|
||
"Comment": "libpolkit-devel is earlier than 0:0.116-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191771003",
|
||
"Comment": "libpolkit-gir is earlier than 0:0.116-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191771004",
|
||
"Comment": "libpolkit-gir-devel is earlier than 0:0.116-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191771005",
|
||
"Comment": "polkit is earlier than 0:0.116-alt1"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |