vuln-list-alt/oval/c9f2/ALT-PU-2019-1492/definitions.json
2024-06-28 13:17:52 +00:00

128 lines
4.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191492",
"Version": "oval:org.altlinux.errata:def:20191492",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1492: package `sqlite3` update to version 3.27.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1492",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1492",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01436",
"RefURL": "https://bdu.fstec.ru/vul/2020-01436",
"Source": "BDU"
},
{
"RefID": "CVE-2019-5018",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-5018",
"Source": "CVE"
}
],
"Description": "This update upgrades sqlite3 to version 3.27.2-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01436: Уязвимость системы управления базами данных SQLite, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-5018: An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.\n\n * #36341: sqlite3: outdated sqlite",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-03-22"
},
"Updated": {
"Date": "2019-03-22"
},
"BDUs": [
{
"ID": "BDU:2020-01436",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2020-01436",
"Impact": "High",
"Public": "20191209"
}
],
"CVEs": [
{
"ID": "CVE-2019-5018",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-5018",
"Impact": "High",
"Public": "20190510"
}
],
"Bugzilla": [
{
"ID": "36341",
"Href": "https://bugzilla.altlinux.org/36341",
"Data": "sqlite3: outdated sqlite"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191492001",
"Comment": "lemon is earlier than 0:3.27.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191492002",
"Comment": "libsqlite3 is earlier than 0:3.27.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191492003",
"Comment": "libsqlite3-devel is earlier than 0:3.27.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191492004",
"Comment": "sqlite3 is earlier than 0:3.27.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191492005",
"Comment": "sqlite3-doc is earlier than 0:3.27.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191492006",
"Comment": "sqlite3-tcl is earlier than 0:3.27.2-alt1"
}
]
}
]
}
}
]
}