2024-12-12 21:07:30 +00:00

119 lines
4.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20221516",
"Version": "oval:org.altlinux.errata:def:20221516",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-1516: package `sqlite3` update to version 3.38.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-1516",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-1516",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-05231",
"RefURL": "https://bdu.fstec.ru/vul/2021-05231",
"Source": "BDU"
},
{
"RefID": "CVE-2021-36690",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-36690",
"Source": "CVE"
}
],
"Description": "This update upgrades sqlite3 to version 3.38.1-alt1. \nSecurity Fix(es):\n\n * BDU:2021-05231: Уязвимость функции idxGetTableInfo компонента командной строки встраиваемой СУБД SQLite, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2021-36690: A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-03-18"
},
"Updated": {
"Date": "2022-03-18"
},
"BDUs": [
{
"ID": "BDU:2021-05231",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-125",
"Href": "https://bdu.fstec.ru/vul/2021-05231",
"Impact": "High",
"Public": "20210707"
}
],
"CVEs": [
{
"ID": "CVE-2021-36690",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-36690",
"Impact": "High",
"Public": "20210824"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20221516001",
"Comment": "lemon is earlier than 0:3.38.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221516002",
"Comment": "libsqlite3 is earlier than 0:3.38.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221516003",
"Comment": "libsqlite3-devel is earlier than 0:3.38.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221516004",
"Comment": "sqlite3 is earlier than 0:3.38.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221516005",
"Comment": "sqlite3-doc is earlier than 0:3.38.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221516006",
"Comment": "tcl-sqlite3 is earlier than 0:3.38.1-alt1"
}
]
}
]
}
}
]
}