2024-06-28 13:17:52 +00:00

133 lines
5.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191373",
"Version": "oval:org.altlinux.errata:def:20191373",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1373: package `monit` update to version 5.25.3-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1373",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1373",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01554",
"RefURL": "https://bdu.fstec.ru/vul/2020-01554",
"Source": "BDU"
},
{
"RefID": "BDU:2020-01555",
"RefURL": "https://bdu.fstec.ru/vul/2020-01555",
"Source": "BDU"
},
{
"RefID": "CVE-2019-11454",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-11454",
"Source": "CVE"
},
{
"RefID": "CVE-2019-11455",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-11455",
"Source": "CVE"
}
],
"Description": "This update upgrades monit to version 5.25.3-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01554: Уязвимость утилиты для управления и мониторинга процессов, программ, файлов и каталогов Monit, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-01555: Уязвимость реализации метода Util_urlDecode утилиты для управления и мониторинга процессов, программ, файлов и каталогов Monit, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-11454: Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticated attacker to introduce arbitrary JavaScript via manipulation of an unsanitized user field of the Authorization header for HTTP Basic Authentication, which is mishandled during an _viewlog operation.\n\n * CVE-2019-11455: A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-03-07"
},
"Updated": {
"Date": "2019-03-07"
},
"BDUs": [
{
"ID": "BDU:2020-01554",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2020-01554",
"Impact": "Low",
"Public": "20190304"
},
{
"ID": "BDU:2020-01555",
"CVSS": "AV:N/AC:L/Au:S/C:C/I:N/A:C",
"CVSS3": "AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2020-01555",
"Impact": "High",
"Public": "20190304"
}
],
"CVEs": [
{
"ID": "CVE-2019-11454",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-11454",
"Impact": "Low",
"Public": "20190422"
},
{
"ID": "CVE-2019-11455",
"CVSS": "AV:N/AC:L/Au:S/C:P/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-11455",
"Impact": "High",
"Public": "20190422"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191373001",
"Comment": "monit is earlier than 0:5.25.3-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191373002",
"Comment": "monit-base is earlier than 0:5.25.3-alt1"
}
]
}
]
}
}
]
}