vuln-list-alt/oval/c9f2/ALT-PU-2014-2028/definitions.json
2024-06-28 13:17:52 +00:00

119 lines
4.5 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20142028",
"Version": "oval:org.altlinux.errata:def:20142028",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2014-2028: package `chromium` update to version 36.0.1985.143-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2014-2028",
"RefURL": "https://errata.altlinux.org/ALT-PU-2014-2028",
"Source": "ALTPU"
},
{
"RefID": "CVE-2014-3165",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3165",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3166",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3166",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3167",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3167",
"Source": "CVE"
}
],
"Description": "This update upgrades chromium to version 36.0.1985.143-alt1. \nSecurity Fix(es):\n\n * CVE-2014-3165: Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementation in Blink, as used in Google Chrome before 36.0.1985.143, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an unexpectedly long lifetime of a temporary object during method completion.\n\n * CVE-2014-3166: The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.\n\n * CVE-2014-3167: Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2014-08-23"
},
"Updated": {
"Date": "2014-08-23"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2014-3165",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3165",
"Impact": "High",
"Public": "20140813"
},
{
"ID": "CVE-2014-3166",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3166",
"Impact": "Low",
"Public": "20140813"
},
{
"ID": "CVE-2014-3167",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3167",
"Impact": "High",
"Public": "20140813"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20142028001",
"Comment": "chromium is earlier than 0:36.0.1985.143-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20142028002",
"Comment": "chromium-gnome is earlier than 0:36.0.1985.143-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20142028003",
"Comment": "chromium-kde is earlier than 0:36.0.1985.143-alt1"
}
]
}
]
}
}
]
}