291 lines
12 KiB
JSON
291 lines
12 KiB
JSON
{
|
||
"Definition": [
|
||
{
|
||
"ID": "oval:org.altlinux.errata:def:20191500",
|
||
"Version": "oval:org.altlinux.errata:def:20191500",
|
||
"Class": "patch",
|
||
"Metadata": {
|
||
"Title": "ALT-PU-2019-1500: package `ceph` update to version 14.2.0-alt1",
|
||
"AffectedList": [
|
||
{
|
||
"Family": "unix",
|
||
"Platforms": [
|
||
"ALT Linux branch c9f2"
|
||
],
|
||
"Products": [
|
||
"ALT SPWorkstation",
|
||
"ALT SPServer"
|
||
]
|
||
}
|
||
],
|
||
"References": [
|
||
{
|
||
"RefID": "ALT-PU-2019-1500",
|
||
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1500",
|
||
"Source": "ALTPU"
|
||
},
|
||
{
|
||
"RefID": "BDU:2021-03718",
|
||
"RefURL": "https://bdu.fstec.ru/vul/2021-03718",
|
||
"Source": "BDU"
|
||
},
|
||
{
|
||
"RefID": "CVE-2018-16889",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-16889",
|
||
"Source": "CVE"
|
||
},
|
||
{
|
||
"RefID": "CVE-2020-12059",
|
||
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-12059",
|
||
"Source": "CVE"
|
||
}
|
||
],
|
||
"Description": "This update upgrades ceph to version 14.2.0-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03718: Уязвимость системы хранения данных Ceph, связанная с ошибками разыменования указателя, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2018-16889: Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.\n\n * CVE-2020-12059: An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.",
|
||
"Advisory": {
|
||
"From": "errata.altlinux.org",
|
||
"Severity": "High",
|
||
"Rights": "Copyright 2024 BaseALT Ltd.",
|
||
"Issued": {
|
||
"Date": "2019-03-24"
|
||
},
|
||
"Updated": {
|
||
"Date": "2019-03-24"
|
||
},
|
||
"BDUs": [
|
||
{
|
||
"ID": "BDU:2021-03718",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
||
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"CWE": "CWE-476",
|
||
"Href": "https://bdu.fstec.ru/vul/2021-03718",
|
||
"Impact": "High",
|
||
"Public": "20200422"
|
||
}
|
||
],
|
||
"CVEs": [
|
||
{
|
||
"ID": "CVE-2018-16889",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
|
||
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
|
||
"CWE": "CWE-532",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-16889",
|
||
"Impact": "High",
|
||
"Public": "20190128"
|
||
},
|
||
{
|
||
"ID": "CVE-2020-12059",
|
||
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
||
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
||
"CWE": "CWE-476",
|
||
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-12059",
|
||
"Impact": "High",
|
||
"Public": "20200422"
|
||
}
|
||
],
|
||
"AffectedCPEs": {
|
||
"CPEs": [
|
||
"cpe:/o:alt:spworkstation:8.4",
|
||
"cpe:/o:alt:spserver:8.4"
|
||
]
|
||
}
|
||
}
|
||
},
|
||
"Criteria": {
|
||
"Operator": "AND",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
||
"Comment": "ALT Linux must be installed"
|
||
}
|
||
],
|
||
"Criterias": [
|
||
{
|
||
"Operator": "OR",
|
||
"Criterions": [
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500001",
|
||
"Comment": "ceph is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500002",
|
||
"Comment": "ceph-base is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500003",
|
||
"Comment": "ceph-common is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500004",
|
||
"Comment": "ceph-devel is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500005",
|
||
"Comment": "ceph-fuse is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500006",
|
||
"Comment": "ceph-mds is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500007",
|
||
"Comment": "ceph-mgr is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500008",
|
||
"Comment": "ceph-mgr-ansible is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500009",
|
||
"Comment": "ceph-mgr-dashboard is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500010",
|
||
"Comment": "ceph-mgr-deepsea is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500011",
|
||
"Comment": "ceph-mgr-diskprediction-local is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500012",
|
||
"Comment": "ceph-mgr-influx is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500013",
|
||
"Comment": "ceph-mgr-insights is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500014",
|
||
"Comment": "ceph-mgr-prometheus is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500015",
|
||
"Comment": "ceph-mgr-restful is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500016",
|
||
"Comment": "ceph-mgr-rook is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500017",
|
||
"Comment": "ceph-mgr-ssh is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500018",
|
||
"Comment": "ceph-mgr-telegraf is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500019",
|
||
"Comment": "ceph-mgr-zabbix is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500020",
|
||
"Comment": "ceph-mon is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500021",
|
||
"Comment": "ceph-osd is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500022",
|
||
"Comment": "ceph-radosgw is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500023",
|
||
"Comment": "ceph-resource-agents is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500024",
|
||
"Comment": "cephfs-shell is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500025",
|
||
"Comment": "grafana-dashboards-ceph is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500026",
|
||
"Comment": "libcephfs-devel is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500027",
|
||
"Comment": "libcephfs2 is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500028",
|
||
"Comment": "librados-devel is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500029",
|
||
"Comment": "librados2 is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500030",
|
||
"Comment": "libradosstriper-devel is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500031",
|
||
"Comment": "libradosstriper1 is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500032",
|
||
"Comment": "librbd-devel is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500033",
|
||
"Comment": "librbd1 is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500034",
|
||
"Comment": "librgw-devel is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500035",
|
||
"Comment": "librgw2 is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500036",
|
||
"Comment": "python3-module-ceph is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500037",
|
||
"Comment": "python3-module-ceph-argparse is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500038",
|
||
"Comment": "python3-module-ceph_volume is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500039",
|
||
"Comment": "python3-module-cephfs is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500040",
|
||
"Comment": "python3-module-rados is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500041",
|
||
"Comment": "python3-module-rbd is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500042",
|
||
"Comment": "python3-module-rgw is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500043",
|
||
"Comment": "rbd-fuse is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500044",
|
||
"Comment": "rbd-mirror is earlier than 0:14.2.0-alt1"
|
||
},
|
||
{
|
||
"TestRef": "oval:org.altlinux.errata:tst:20191500045",
|
||
"Comment": "rbd-nbd is earlier than 0:14.2.0-alt1"
|
||
}
|
||
]
|
||
}
|
||
]
|
||
}
|
||
}
|
||
]
|
||
} |