vuln-list-alt/oval/c9f2/ALT-PU-2014-1955/definitions.json
2024-12-12 21:07:30 +00:00

438 lines
21 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20141955",
"Version": "oval:org.altlinux.errata:def:20141955",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2014-1955: package `chromium` update to version 36.0.1985.125-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2014-1955",
"RefURL": "https://errata.altlinux.org/ALT-PU-2014-1955",
"Source": "ALTPU"
},
{
"RefID": "BDU:2014-00137",
"RefURL": "https://bdu.fstec.ru/vul/2014-00137",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00148",
"RefURL": "https://bdu.fstec.ru/vul/2014-00148",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00151",
"RefURL": "https://bdu.fstec.ru/vul/2014-00151",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00155",
"RefURL": "https://bdu.fstec.ru/vul/2014-00155",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00157",
"RefURL": "https://bdu.fstec.ru/vul/2014-00157",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00182",
"RefURL": "https://bdu.fstec.ru/vul/2014-00182",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00195",
"RefURL": "https://bdu.fstec.ru/vul/2014-00195",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00209",
"RefURL": "https://bdu.fstec.ru/vul/2014-00209",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00330",
"RefURL": "https://bdu.fstec.ru/vul/2014-00330",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00331",
"RefURL": "https://bdu.fstec.ru/vul/2014-00331",
"Source": "BDU"
},
{
"RefID": "BDU:2014-00332",
"RefURL": "https://bdu.fstec.ru/vul/2014-00332",
"Source": "BDU"
},
{
"RefID": "BDU:2015-00199",
"RefURL": "https://bdu.fstec.ru/vul/2015-00199",
"Source": "BDU"
},
{
"RefID": "BDU:2015-00243",
"RefURL": "https://bdu.fstec.ru/vul/2015-00243",
"Source": "BDU"
},
{
"RefID": "CVE-2014-1743",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1743",
"Source": "CVE"
},
{
"RefID": "CVE-2014-1744",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1744",
"Source": "CVE"
},
{
"RefID": "CVE-2014-1745",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1745",
"Source": "CVE"
},
{
"RefID": "CVE-2014-1746",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1746",
"Source": "CVE"
},
{
"RefID": "CVE-2014-1747",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1747",
"Source": "CVE"
},
{
"RefID": "CVE-2014-1748",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1748",
"Source": "CVE"
},
{
"RefID": "CVE-2014-1749",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-1749",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3152",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3152",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3154",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3154",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3155",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3155",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3156",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3156",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3157",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3157",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3160",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3160",
"Source": "CVE"
},
{
"RefID": "CVE-2014-3803",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2014-3803",
"Source": "CVE"
}
],
"Description": "This update upgrades chromium to version 36.0.1985.125-alt1. \nSecurity Fix(es):\n\n * BDU:2014-00137: Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании\n\n * BDU:2014-00148: Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании\n\n * BDU:2014-00151: Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании\n\n * BDU:2014-00155: Уязвимость браузера Google Chrome, позволяющая злоумышленнику внедрить произвольный веб-сценарий или HTML-код\n\n * BDU:2014-00157: Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании\n\n * BDU:2014-00182: Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании\n\n * BDU:2014-00195: Уязвимость браузера Google Chrome, позволяющая злоумышленнику подменить интерфейс пользователя\n\n * BDU:2014-00209: Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании\n\n * BDU:2014-00330: Уязвимость браузера Google Chrome, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2014-00331: Уязвимость браузера Google Chrome, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2014-00332: Уязвимость браузера Google Chrome, позволяющая злоумышленнику выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2015-00199: Уязвимости браузера Google Chrome, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации\n\n * BDU:2015-00243: Уязвимость браузера Google Chrome, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации\n\n * CVE-2014-1743: Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers tree mutation.\n\n * CVE-2014-1744: Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large shared-memory allocation.\n\n * CVE-2014-1745: Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFontFaceElement object, related to core/svg/SVGFontFaceElement.cpp.\n\n * CVE-2014-1746: The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently large integer data type, which allows remote attackers to cause a denial of service (out-of-bounds read) via vectors that trigger use of a large buffer.\n\n * CVE-2014-1747: Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka \"Universal XSS (UXSS).\"\n\n * CVE-2014-1748: The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.\n\n * CVE-2014-1749: Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.\n\n * CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.\n\n * CVE-2014-3154: Use-after-free vulnerability in the ChildThread::Shutdown function in content/child/child_thread.cc in the filesystem API in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to a Blink shutdown.\n\n * CVE-2014-3155: net/spdy/spdy_write_queue.cc in the SPDY implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging incorrect queue maintenance.\n\n * CVE-2014-3156: Buffer overflow in the clipboard implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger unexpected bitmap data, related to content/renderer/renderer_clipboard_client.cc and content/renderer/webclipboard_impl.cc.\n\n * CVE-2014-3157: Heap-based buffer overflow in the FFmpegVideoDecoder::GetVideoBuffer function in media/filters/ffmpeg_video_decoder.cc in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging VideoFrame data structures that are too small for proper interaction with an underlying FFmpeg library.\n\n * CVE-2014-3160: The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.\n\n * CVE-2014-3803: The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.\n\n * #30182: Не верный перевод в chromium",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2014-07-25"
},
"Updated": {
"Date": "2014-07-25"
},
"BDUs": [
{
"ID": "BDU:2014-00137",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://bdu.fstec.ru/vul/2014-00137",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "BDU:2014-00148",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CWE": "CWE-287",
"Href": "https://bdu.fstec.ru/vul/2014-00148",
"Impact": "Low",
"Public": "20140611"
},
{
"ID": "BDU:2014-00151",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-399",
"Href": "https://bdu.fstec.ru/vul/2014-00151",
"Impact": "High",
"Public": "20140611"
},
{
"ID": "BDU:2014-00155",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2014-00155",
"Impact": "Low",
"Public": "20140521"
},
{
"ID": "BDU:2014-00157",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2014-00157",
"Impact": "Low",
"Public": "20140521"
},
{
"ID": "BDU:2014-00182",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://bdu.fstec.ru/vul/2014-00182",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "BDU:2014-00195",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CWE": "CWE-445",
"Href": "https://bdu.fstec.ru/vul/2014-00195",
"Impact": "Low",
"Public": "20140521"
},
{
"ID": "BDU:2014-00209",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2014-00209",
"Impact": "High",
"Public": "20140611"
},
{
"ID": "BDU:2014-00330",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-399",
"Href": "https://bdu.fstec.ru/vul/2014-00330",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "BDU:2014-00331",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2014-00331",
"Impact": "High",
"Public": "20140321"
},
{
"ID": "BDU:2014-00332",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-399",
"Href": "https://bdu.fstec.ru/vul/2014-00332",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "BDU:2015-00199",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"Href": "https://bdu.fstec.ru/vul/2015-00199",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "BDU:2015-00243",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-264",
"Href": "https://bdu.fstec.ru/vul/2015-00243",
"Impact": "High",
"Public": "20140720"
}
],
"CVEs": [
{
"ID": "CVE-2014-1743",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-399",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1743",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "CVE-2014-1744",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1744",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "CVE-2014-1745",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-399",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1745",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "CVE-2014-1746",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1746",
"Impact": "Low",
"Public": "20140521"
},
{
"ID": "CVE-2014-1747",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1747",
"Impact": "Low",
"Public": "20140521"
},
{
"ID": "CVE-2014-1748",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1748",
"Impact": "Low",
"Public": "20140521"
},
{
"ID": "CVE-2014-1749",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-1749",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "CVE-2014-3152",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3152",
"Impact": "High",
"Public": "20140521"
},
{
"ID": "CVE-2014-3154",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3154",
"Impact": "High",
"Public": "20140611"
},
{
"ID": "CVE-2014-3155",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3155",
"Impact": "Low",
"Public": "20140611"
},
{
"ID": "CVE-2014-3156",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3156",
"Impact": "High",
"Public": "20140611"
},
{
"ID": "CVE-2014-3157",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3157",
"Impact": "High",
"Public": "20140611"
},
{
"ID": "CVE-2014-3160",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CWE": "CWE-264",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3160",
"Impact": "Low",
"Public": "20140720"
},
{
"ID": "CVE-2014-3803",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2014-3803",
"Impact": "Low",
"Public": "20140521"
}
],
"Bugzilla": [
{
"ID": "30182",
"Href": "https://bugzilla.altlinux.org/30182",
"Data": "Не верный перевод в chromium"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20141955001",
"Comment": "chromium is earlier than 0:36.0.1985.125-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20141955002",
"Comment": "chromium-gnome is earlier than 0:36.0.1985.125-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20141955003",
"Comment": "chromium-kde is earlier than 0:36.0.1985.125-alt1"
}
]
}
]
}
}
]
}