2024-12-12 21:07:30 +00:00

112 lines
3.8 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20131030",
"Version": "oval:org.altlinux.errata:def:20131030",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2013-1030: package `nss` update to version 3.15.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2013-1030",
"RefURL": "https://errata.altlinux.org/ALT-PU-2013-1030",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-02928",
"RefURL": "https://bdu.fstec.ru/vul/2015-02928",
"Source": "BDU"
},
{
"RefID": "CVE-2013-1739",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2013-1739",
"Source": "CVE"
}
],
"Description": "This update upgrades nss to version 3.15.2-alt1. \nSecurity Fix(es):\n\n * BDU:2015-02928: Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации\n\n * CVE-2013-1739: Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2013-10-26"
},
"Updated": {
"Date": "2013-10-26"
},
"BDUs": [
{
"ID": "BDU:2015-02928",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"Href": "https://bdu.fstec.ru/vul/2015-02928",
"Impact": "Low",
"Public": "20131022"
}
],
"CVEs": [
{
"ID": "CVE-2013-1739",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2013-1739",
"Impact": "Low",
"Public": "20131022"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20131030001",
"Comment": "libnss is earlier than 0:3.15.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20131030002",
"Comment": "libnss-devel is earlier than 0:3.15.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20131030003",
"Comment": "libnss-devel-static is earlier than 0:3.15.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20131030004",
"Comment": "libnss-sysinit is earlier than 0:3.15.2-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20131030005",
"Comment": "nss-utils is earlier than 0:3.15.2-alt1"
}
]
}
]
}
}
]
}