254 lines
10 KiB
JSON
254 lines
10 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20202740",
|
|
"Version": "oval:org.altlinux.errata:def:20202740",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2020-2740: package `libvirt` update to version 6.7.0-alt1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch p10"
|
|
],
|
|
"Products": [
|
|
"ALT Server",
|
|
"ALT Virtualization Server",
|
|
"ALT Workstation",
|
|
"ALT Workstation K",
|
|
"ALT Education",
|
|
"Simply Linux",
|
|
"Starterkit"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2020-2740",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-2740",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2020-14339",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-14339",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades libvirt to version 6.7.0-alt1. \nSecurity Fix(es):\n\n * CVE-2020-14339: A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "High",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2020-09-07"
|
|
},
|
|
"Updated": {
|
|
"Date": "2020-09-07"
|
|
},
|
|
"BDUs": null,
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2020-14339",
|
|
"CVSS": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
|
|
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
|
|
"CWE": "CWE-772",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-14339",
|
|
"Impact": "High",
|
|
"Public": "20201203"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:kworkstation:10",
|
|
"cpe:/o:alt:workstation:10",
|
|
"cpe:/o:alt:server:10",
|
|
"cpe:/o:alt:server-v:10",
|
|
"cpe:/o:alt:education:10",
|
|
"cpe:/o:alt:slinux:10",
|
|
"cpe:/o:alt:starterkit:p10",
|
|
"cpe:/o:alt:kworkstation:10.1",
|
|
"cpe:/o:alt:workstation:10.1",
|
|
"cpe:/o:alt:server:10.1",
|
|
"cpe:/o:alt:server-v:10.1",
|
|
"cpe:/o:alt:education:10.1",
|
|
"cpe:/o:alt:slinux:10.1",
|
|
"cpe:/o:alt:starterkit:10.1",
|
|
"cpe:/o:alt:kworkstation:10.2",
|
|
"cpe:/o:alt:workstation:10.2",
|
|
"cpe:/o:alt:server:10.2",
|
|
"cpe:/o:alt:server-v:10.2",
|
|
"cpe:/o:alt:education:10.2",
|
|
"cpe:/o:alt:slinux:10.2",
|
|
"cpe:/o:alt:starterkit:10.2"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:2001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740001",
|
|
"Comment": "libvirt is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740002",
|
|
"Comment": "libvirt-admin is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740003",
|
|
"Comment": "libvirt-client is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740004",
|
|
"Comment": "libvirt-daemon is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740005",
|
|
"Comment": "libvirt-daemon-config-network is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740006",
|
|
"Comment": "libvirt-daemon-config-nwfilter is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740007",
|
|
"Comment": "libvirt-daemon-driver-interface is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740008",
|
|
"Comment": "libvirt-daemon-driver-lxc is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740009",
|
|
"Comment": "libvirt-daemon-driver-network is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740010",
|
|
"Comment": "libvirt-daemon-driver-nodedev is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740011",
|
|
"Comment": "libvirt-daemon-driver-nwfilter is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740012",
|
|
"Comment": "libvirt-daemon-driver-qemu is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740013",
|
|
"Comment": "libvirt-daemon-driver-secret is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740014",
|
|
"Comment": "libvirt-daemon-driver-storage is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740015",
|
|
"Comment": "libvirt-daemon-driver-storage-core is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740016",
|
|
"Comment": "libvirt-daemon-driver-storage-disk is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740017",
|
|
"Comment": "libvirt-daemon-driver-storage-fs is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740018",
|
|
"Comment": "libvirt-daemon-driver-storage-gluster is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740019",
|
|
"Comment": "libvirt-daemon-driver-storage-iscsi is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740020",
|
|
"Comment": "libvirt-daemon-driver-storage-iscsi-direct is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740021",
|
|
"Comment": "libvirt-daemon-driver-storage-logical is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740022",
|
|
"Comment": "libvirt-daemon-driver-storage-mpath is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740023",
|
|
"Comment": "libvirt-daemon-driver-storage-rbd is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740024",
|
|
"Comment": "libvirt-daemon-driver-storage-scsi is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740025",
|
|
"Comment": "libvirt-daemon-driver-storage-zfs is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740026",
|
|
"Comment": "libvirt-daemon-driver-vbox is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740027",
|
|
"Comment": "libvirt-devel is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740028",
|
|
"Comment": "libvirt-docs is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740029",
|
|
"Comment": "libvirt-kvm is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740030",
|
|
"Comment": "libvirt-libs is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740031",
|
|
"Comment": "libvirt-lock-sanlock is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740032",
|
|
"Comment": "libvirt-login-shell is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740033",
|
|
"Comment": "libvirt-lxc is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740034",
|
|
"Comment": "libvirt-qemu is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740035",
|
|
"Comment": "libvirt-qemu-common is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740036",
|
|
"Comment": "libvirt-vbox is earlier than 0:6.7.0-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20202740037",
|
|
"Comment": "nss-libvirt is earlier than 0:6.7.0-alt1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |