vuln-list-alt/oval/c9f2/ALT-PU-2017-2174/definitions.json
2024-06-28 13:17:52 +00:00

104 lines
3.5 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172174",
"Version": "oval:org.altlinux.errata:def:20172174",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2174: package `SPICE` update to version 0.13.90-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2174",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2174",
"Source": "ALTPU"
},
{
"RefID": "CVE-2016-9577",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-9577",
"Source": "CVE"
},
{
"RefID": "CVE-2016-9578",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-9578",
"Source": "CVE"
}
],
"Description": "This update upgrades SPICE to version 0.13.90-alt1. \nSecurity Fix(es):\n\n * CVE-2016-9577: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.\n\n * CVE-2016-9578: A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-09-08"
},
"Updated": {
"Date": "2017-09-08"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2016-9577",
"CVSS": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-9577",
"Impact": "High",
"Public": "20180727"
},
{
"ID": "CVE-2016-9578",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-9578",
"Impact": "High",
"Public": "20180727"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172174001",
"Comment": "libspice-server is earlier than 0:0.13.90-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172174002",
"Comment": "libspice-server-devel is earlier than 0:0.13.90-alt1"
}
]
}
]
}
}
]
}