vuln-list-alt/oval/c9f2/ALT-PU-2020-1381/definitions.json
2024-06-28 13:17:52 +00:00

127 lines
4.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20201381",
"Version": "oval:org.altlinux.errata:def:20201381",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-1381: package `qt5-webview` update to version 5.12.7-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-1381",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-1381",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-01758",
"RefURL": "https://bdu.fstec.ru/vul/2022-01758",
"Source": "BDU"
},
{
"RefID": "CVE-2020-0570",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-0570",
"Source": "CVE"
},
{
"RefID": "CVE-2020-24742",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-24742",
"Source": "CVE"
}
],
"Description": "This update upgrades qt5-webview to version 5.12.7-alt1. \nSecurity Fix(es):\n\n * BDU:2022-01758: Уязвимость компонента QPluginLoader кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2020-0570: Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.\n\n * CVE-2020-24742: An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-02-26"
},
"Updated": {
"Date": "2020-02-26"
},
"BDUs": [
{
"ID": "BDU:2022-01758",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2022-01758",
"Impact": "High",
"Public": "20210809"
}
],
"CVEs": [
{
"ID": "CVE-2020-0570",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-426",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-0570",
"Impact": "High",
"Public": "20200914"
},
{
"ID": "CVE-2020-24742",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-24742",
"Impact": "High",
"Public": "20210809"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20201381001",
"Comment": "libqt5-webview is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201381002",
"Comment": "qt5-webview-common is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201381003",
"Comment": "qt5-webview-devel is earlier than 0:5.12.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20201381004",
"Comment": "qt5-webview-doc is earlier than 0:5.12.7-alt1"
}
]
}
]
}
}
]
}