vuln-list-alt/oval/c9f2/ALT-PU-2014-2435/definitions.json
2024-06-28 13:17:52 +00:00

169 lines
7.1 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20142435",
"Version": "oval:org.altlinux.errata:def:20142435",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2014-2435: package `adobe-flash-player` update to version 11-alt37",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2014-2435",
"RefURL": "https://errata.altlinux.org/ALT-PU-2014-2435",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-04945",
"RefURL": "https://bdu.fstec.ru/vul/2021-04945",
"Source": "BDU"
},
{
"RefID": "CVE-2014-0580",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-0580",
"Source": "CVE"
},
{
"RefID": "CVE-2014-0587",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-0587",
"Source": "CVE"
},
{
"RefID": "CVE-2014-8443",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-8443",
"Source": "CVE"
},
{
"RefID": "CVE-2014-9162",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-9162",
"Source": "CVE"
},
{
"RefID": "CVE-2014-9163",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-9163",
"Source": "CVE"
},
{
"RefID": "CVE-2014-9164",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-9164",
"Source": "CVE"
}
],
"Description": "This update upgrades adobe-flash-player to version 11-alt37. \nSecurity Fix(es):\n\n * BDU:2021-04945: Уязвимость программной платформы Adobe Flash Player, связанная с выходом операции за границы буфера, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2014-0580: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.\n\n * CVE-2014-0587: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-9164.\n\n * CVE-2014-8443: Use-after-free vulnerability in Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors.\n\n * CVE-2014-9162: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to obtain sensitive information via unspecified vectors.\n\n * CVE-2014-9163: Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.\n\n * CVE-2014-9164: Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0587.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2014-12-10"
},
"Updated": {
"Date": "2014-12-10"
},
"BDUs": [
{
"ID": "BDU:2021-04945",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2021-04945",
"Impact": "Critical",
"Public": "20141209"
}
],
"CVEs": [
{
"ID": "CVE-2014-0580",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-264",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-0580",
"Impact": "Critical",
"Public": "20141210"
},
{
"ID": "CVE-2014-0587",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-94",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-0587",
"Impact": "Critical",
"Public": "20141210"
},
{
"ID": "CVE-2014-8443",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-8443",
"Impact": "Critical",
"Public": "20141210"
},
{
"ID": "CVE-2014-9162",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-9162",
"Impact": "Critical",
"Public": "20141210"
},
{
"ID": "CVE-2014-9163",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-9163",
"Impact": "Critical",
"Public": "20141210"
},
{
"ID": "CVE-2014-9164",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-94",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-9164",
"Impact": "Critical",
"Public": "20141210"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20142435001",
"Comment": "i586-mozilla-plugin-adobe-flash is earlier than 3:11.2.202.425-alt37"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20142435002",
"Comment": "mozilla-plugin-adobe-flash is earlier than 3:11.2.202.425-alt37"
}
]
}
]
}
}
]
}