2024-12-12 21:07:30 +00:00

159 lines
6.0 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20161598",
"Version": "oval:org.altlinux.errata:def:20161598",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2016-1598: package `glibc` update to version 2.23-alt3",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2016-1598",
"RefURL": "https://errata.altlinux.org/ALT-PU-2016-1598",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-04623",
"RefURL": "https://bdu.fstec.ru/vul/2022-04623",
"Source": "BDU"
},
{
"RefID": "CVE-2016-4429",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-4429",
"Source": "CVE"
}
],
"Description": "This update upgrades glibc to version 2.23-alt3. \nSecurity Fix(es):\n\n * BDU:2022-04623: Уязвимость функции clntudp_call (sunrpc/clnt_udp.c) в библиотеке GNU C (glibc или libc6), связанная с записью за границами буфера в памяти, позволяющая нарушителю вводить и выполнять произвольные команды или вызвать отказ в обслуживании\n\n * CVE-2016-4429: Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2016-06-10"
},
"Updated": {
"Date": "2016-06-10"
},
"BDUs": [
{
"ID": "BDU:2022-04623",
"CVSS": "AV:N/AC:H/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-404, CWE-787",
"Href": "https://bdu.fstec.ru/vul/2022-04623",
"Impact": "Low",
"Public": "20160518"
}
],
"CVEs": [
{
"ID": "CVE-2016-4429",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-4429",
"Impact": "Low",
"Public": "20160610"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20161598001",
"Comment": "glibc is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598002",
"Comment": "glibc-core is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598003",
"Comment": "glibc-debug is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598004",
"Comment": "glibc-devel is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598005",
"Comment": "glibc-devel-static is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598006",
"Comment": "glibc-doc is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598007",
"Comment": "glibc-gconv-modules is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598008",
"Comment": "glibc-i18ndata is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598009",
"Comment": "glibc-locales is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598010",
"Comment": "glibc-nss is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598011",
"Comment": "glibc-preinstall is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598012",
"Comment": "glibc-pthread is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598013",
"Comment": "glibc-timezones is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598014",
"Comment": "glibc-utils is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598015",
"Comment": "iconv is earlier than 6:2.23-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20161598016",
"Comment": "nscd is earlier than 6:2.23-alt3"
}
]
}
]
}
}
]
}