137 lines
5.1 KiB
JSON
137 lines
5.1 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20191203",
|
|
"Version": "oval:org.altlinux.errata:def:20191203",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2019-1203: package `libwebkitgtk4` update to version 2.22.6-alt1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch c9f2"
|
|
],
|
|
"Products": [
|
|
"ALT SPWorkstation",
|
|
"ALT SPServer"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2019-1203",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1203",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2019-01028",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2019-01028",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2019-6234",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-6234",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades libwebkitgtk4 to version 2.22.6-alt1. \nSecurity Fix(es):\n\n * BDU:2019-01028: Уязвимость модуля отображения WebKit, вызванная выходом операции за границы буфера в памяти, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2019-6234: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "High",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2019-02-10"
|
|
},
|
|
"Updated": {
|
|
"Date": "2019-02-10"
|
|
},
|
|
"BDUs": [
|
|
{
|
|
"ID": "BDU:2019-01028",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
|
|
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2019-01028",
|
|
"Impact": "High",
|
|
"Public": "20190211"
|
|
}
|
|
],
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2019-6234",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-787",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-6234",
|
|
"Impact": "High",
|
|
"Public": "20190305"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:spworkstation:8.4",
|
|
"cpe:/o:alt:spserver:8.4"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203001",
|
|
"Comment": "jsc4 is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203002",
|
|
"Comment": "libjavascriptcoregtk4 is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203003",
|
|
"Comment": "libjavascriptcoregtk4-devel is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203004",
|
|
"Comment": "libjavascriptcoregtk4-gir is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203005",
|
|
"Comment": "libjavascriptcoregtk4-gir-devel is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203006",
|
|
"Comment": "libwebkit2gtk is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203007",
|
|
"Comment": "libwebkit2gtk-devel is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203008",
|
|
"Comment": "libwebkit2gtk-gir is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203009",
|
|
"Comment": "libwebkit2gtk-gir-devel is earlier than 0:2.22.6-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20191203010",
|
|
"Comment": "webkitgtk-minibrowser is earlier than 0:2.22.6-alt1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |