vuln-list-alt/oval/c9f2/ALT-PU-2014-2128/definitions.json
2024-12-12 21:07:30 +00:00

129 lines
5.0 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20142128",
"Version": "oval:org.altlinux.errata:def:20142128",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2014-2128: package `libmodplug` update to version 0.8.8.5-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2014-2128",
"RefURL": "https://errata.altlinux.org/ALT-PU-2014-2128",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-03019",
"RefURL": "https://bdu.fstec.ru/vul/2015-03019",
"Source": "BDU"
},
{
"RefID": "BDU:2015-09742",
"RefURL": "https://bdu.fstec.ru/vul/2015-09742",
"Source": "BDU"
},
{
"RefID": "CVE-2013-4233",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2013-4233",
"Source": "CVE"
},
{
"RefID": "CVE-2013-4234",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2013-4234",
"Source": "CVE"
}
],
"Description": "This update upgrades libmodplug to version 0.8.8.5-alt1. \nSecurity Fix(es):\n\n * BDU:2015-03019: Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации\n\n * BDU:2015-09742: Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации\n\n * CVE-2013-4233: Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-based buffer overflow.\n\n * CVE-2013-4234: Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted ABC.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2014-09-11"
},
"Updated": {
"Date": "2014-09-11"
},
"BDUs": [
{
"ID": "BDU:2015-03019",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://bdu.fstec.ru/vul/2015-03019",
"Impact": "Low",
"Public": "20130916"
},
{
"ID": "BDU:2015-09742",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://bdu.fstec.ru/vul/2015-09742",
"Impact": "Low",
"Public": "20140816"
}
],
"CVEs": [
{
"ID": "CVE-2013-4233",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CWE": "CWE-189",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2013-4233",
"Impact": "Low",
"Public": "20130916"
},
{
"ID": "CVE-2013-4234",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2013-4234",
"Impact": "Low",
"Public": "20130916"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20142128001",
"Comment": "libmodplug is earlier than 0:0.8.8.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20142128002",
"Comment": "libmodplug-devel is earlier than 0:0.8.8.5-alt1"
}
]
}
]
}
}
]
}