2024-12-12 21:07:30 +00:00

83 lines
2.9 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20242022",
"Version": "oval:org.altlinux.errata:def:20242022",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-2022: package `python3-module-fastapi` update to version 0.109.2-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-2022",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-2022",
"Source": "ALTPU"
},
{
"RefID": "CVE-2024-24762",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2024-24762",
"Source": "CVE"
}
],
"Description": "This update upgrades python3-module-fastapi to version 0.109.2-alt1. \nSecurity Fix(es):\n\n * CVE-2024-24762: `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests, leading to regular expression denial of service. This vulnerability has been patched in version 0.0.7.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-02-09"
},
"Updated": {
"Date": "2024-02-09"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2024-24762",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-1333",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2024-24762",
"Impact": "High",
"Public": "20240205"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20242022001",
"Comment": "python3-module-fastapi is earlier than 0:0.109.2-alt1"
}
]
}
]
}
}
]
}