vuln-list-alt/oval/c9f2/ALT-PU-2019-1709/definitions.json
2024-12-12 21:07:30 +00:00

113 lines
4.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20191709",
"Version": "oval:org.altlinux.errata:def:20191709",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-1709: package `python-module-urllib3` update to version 1.24.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-1709",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-1709",
"Source": "ALTPU"
},
{
"RefID": "BDU:2019-02105",
"RefURL": "https://bdu.fstec.ru/vul/2019-02105",
"Source": "BDU"
},
{
"RefID": "CVE-2019-11324",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-11324",
"Source": "CVE"
}
],
"Description": "This update upgrades python-module-urllib3 to version 1.24.2-alt1. \nSecurity Fix(es):\n\n * BDU:2019-02105: Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю установить SSL-соединение\n\n * CVE-2019-11324: The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-04-22"
},
"Updated": {
"Date": "2019-04-22"
},
"BDUs": [
{
"ID": "BDU:2019-02105",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2019-02105",
"Impact": "High",
"Public": "20190418"
}
],
"CVEs": [
{
"ID": "CVE-2019-11324",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-11324",
"Impact": "High",
"Public": "20190418"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20191709001",
"Comment": "python-module-urllib3 is earlier than 2:1.24.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191709002",
"Comment": "python-module-urllib3-docs is earlier than 2:1.24.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191709003",
"Comment": "python-module-urllib3-pickles is earlier than 2:1.24.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20191709004",
"Comment": "python3-module-urllib3 is earlier than 2:1.24.2-alt1"
}
]
}
]
}
}
]
}