vuln-list-alt/oval/c9f2/ALT-PU-2017-2813/definitions.json
2024-06-28 13:17:52 +00:00

403 lines
19 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172813",
"Version": "oval:org.altlinux.errata:def:20172813",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2813: package `chromium` update to version 63.0.3239.108-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2813",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2813",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-01485",
"RefURL": "https://bdu.fstec.ru/vul/2018-01485",
"Source": "BDU"
},
{
"RefID": "CVE-2017-15407",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15407",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15408",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15408",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15409",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15409",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15410",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15410",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15411",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15411",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15412",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15412",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15413",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15413",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15415",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15415",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15416",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15416",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15417",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15417",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15418",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15418",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15419",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15419",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15420",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15420",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15422",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15422",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15423",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15423",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15424",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15424",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15425",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15425",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15426",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15426",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15427",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15427",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15428",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15428",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15429",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15429",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15430",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15430",
"Source": "CVE"
}
],
"Description": "This update upgrades chromium to version 63.0.3239.108-alt1. \nSecurity Fix(es):\n\n * BDU:2018-01485: Уязвимость библиотеки International Components for Unicode, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * CVE-2017-15407: Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.\n\n * CVE-2017-15408: Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.\n\n * CVE-2017-15409: Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\n\n * CVE-2017-15410: Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.\n\n * CVE-2017-15411: Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.\n\n * CVE-2017-15412: Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\n\n * CVE-2017-15413: Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.\n\n * CVE-2017-15415: Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.\n\n * CVE-2017-15416: Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka a Blink out-of-bounds read.\n\n * CVE-2017-15417: Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origin data via a crafted HTML page.\n\n * CVE-2017-15418: Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.\n\n * CVE-2017-15419: Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.\n\n * CVE-2017-15420: Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.\n\n * CVE-2017-15422: Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.\n\n * CVE-2017-15423: Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.\n\n * CVE-2017-15424: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.\n\n * CVE-2017-15425: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.\n\n * CVE-2017-15426: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.\n\n * CVE-2017-15427: Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.\n\n * CVE-2017-15428: Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.\n\n * CVE-2017-15429: Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.\n\n * CVE-2017-15430: Insufficient data validation in Chromecast plugin in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-12-19"
},
"Updated": {
"Date": "2017-12-19"
},
"BDUs": [
{
"ID": "BDU:2018-01485",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-190, CWE-254",
"Href": "https://bdu.fstec.ru/vul/2018-01485",
"Impact": "Low",
"Public": "20171206"
}
],
"CVEs": [
{
"ID": "CVE-2017-15407",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15407",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15408",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15408",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15409",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15409",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15410",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15410",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15411",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15411",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15412",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15412",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15413",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-704",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15413",
"Impact": "High",
"Public": "20180828"
},
{
"ID": "CVE-2017-15415",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15415",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15416",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15416",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15417",
"CVSS": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15417",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15418",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15418",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15419",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"CWE": "CWE-601",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15419",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15420",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15420",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15422",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-190",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15422",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15423",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-310",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15423",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15424",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15424",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15425",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15425",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15426",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15426",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15427",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15427",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15428",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15428",
"Impact": "High",
"Public": "20190109"
},
{
"ID": "CVE-2017-15429",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15429",
"Impact": "Low",
"Public": "20180828"
},
{
"ID": "CVE-2017-15430",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15430",
"Impact": "Low",
"Public": "20180828"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172813001",
"Comment": "chromium is earlier than 0:63.0.3239.108-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172813002",
"Comment": "chromium-gnome is earlier than 0:63.0.3239.108-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172813003",
"Comment": "chromium-kde is earlier than 0:63.0.3239.108-alt1"
}
]
}
]
}
}
]
}