2024-06-28 13:17:52 +00:00

121 lines
4.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20182604",
"Version": "oval:org.altlinux.errata:def:20182604",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-2604: package `libopenjpeg2.0` update to version 2.3.0-alt2",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-2604",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-2604",
"Source": "ALTPU"
},
{
"RefID": "BDU:2019-01576",
"RefURL": "https://bdu.fstec.ru/vul/2019-01576",
"Source": "BDU"
},
{
"RefID": "CVE-2018-5785",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-5785",
"Source": "CVE"
}
],
"Description": "This update upgrades libopenjpeg2.0 to version 2.3.0-alt2. \nSecurity Fix(es):\n\n * BDU:2019-01576: Уязвимость функции opj_j2k_setup_encoder библиотеки для кодирования и декодирования изображений OpenJPEG, связанная с целочисленным переполнением, вызванным левым сдвигом, позволяющая нарушителю вызывать отказ в обслуживании\n\n * CVE-2018-5785: In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.\n\n * #35585: Переименованы файлы\n\n * #35586: Требует статическуу библиотека",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-11-07"
},
"Updated": {
"Date": "2018-11-07"
},
"BDUs": [
{
"ID": "BDU:2019-01576",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-190",
"Href": "https://bdu.fstec.ru/vul/2019-01576",
"Impact": "Low",
"Public": "20180119"
}
],
"CVEs": [
{
"ID": "CVE-2018-5785",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-190",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-5785",
"Impact": "Low",
"Public": "20180119"
}
],
"Bugzilla": [
{
"ID": "35585",
"Href": "https://bugzilla.altlinux.org/35585",
"Data": "Переименованы файлы"
},
{
"ID": "35586",
"Href": "https://bugzilla.altlinux.org/35586",
"Data": "Требует статическуу библиотека"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20182604001",
"Comment": "libopenjpeg2.0 is earlier than 0:2.3.0-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182604002",
"Comment": "libopenjpeg2.0-devel is earlier than 0:2.3.0-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182604003",
"Comment": "openjpeg-tools2.0 is earlier than 0:2.3.0-alt2"
}
]
}
]
}
}
]
}