vuln-list-alt/oval/c9f2/ALT-PU-2019-1002/definitions.json
2024-12-12 21:07:30 +00:00

156 lines
6.7 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191002",
"Version": "oval:org.altlinux.errata:def:20191002",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1002: package `haproxy` update to version 1.9.0-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1002",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1002",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03308",
"RefURL": "https://bdu.fstec.ru/vul/2020-03308",
"Source": "BDU"
},
{
"RefID": "BDU:2020-03309",
"RefURL": "https://bdu.fstec.ru/vul/2020-03309",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01442",
"RefURL": "https://bdu.fstec.ru/vul/2021-01442",
"Source": "BDU"
},
{
"RefID": "CVE-2018-14645",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-14645",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20102",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20102",
"Source": "CVE"
},
{
"RefID": "CVE-2018-20103",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-20103",
"Source": "CVE"
}
],
"Description": "This update upgrades haproxy to version 1.9.0-alt1. \nSecurity Fix(es):\n\n * BDU:2020-03308: Уязвимость компонента dns.c сетевого программного обеспечения HAProxy, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-03309: Уязвимость функции dns_validate_dns_response компонента dns.c сетевого программного обеспечения HAProxy, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации\n\n * BDU:2021-01442: Уязвимость HPACK декодера серверного программного обеспечения HAProxy, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2018-14645: A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.\n\n * CVE-2018-20102: An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past the end of the 8193-byte buffer, depending on the value of accepted_payload_size.\n\n * CVE-2018-20103: An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-01-03"
},
"Updated": {
"Date": "2019-01-03"
},
"BDUs": [
{
"ID": "BDU:2020-03308",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"CWE": "CWE-400, CWE-835",
"Href": "https://bdu.fstec.ru/vul/2020-03308",
"Impact": "Low",
"Public": "20181212"
},
{
"ID": "BDU:2020-03309",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2020-03309",
"Impact": "Low",
"Public": "20181212"
},
{
"ID": "BDU:2021-01442",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2021-01442",
"Impact": "High",
"Public": "20180921"
}
],
"CVEs": [
{
"ID": "CVE-2018-14645",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-14645",
"Impact": "High",
"Public": "20180921"
},
{
"ID": "CVE-2018-20102",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20102",
"Impact": "High",
"Public": "20181212"
},
{
"ID": "CVE-2018-20103",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-835",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-20103",
"Impact": "High",
"Public": "20181212"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191002001",
"Comment": "haproxy is earlier than 0:1.9.0-alt1"
}
]
}
]
}
}
]
}