vuln-list-alt/oval/p11/ALT-PU-2015-2088/definitions.json
2024-12-12 21:07:30 +00:00

183 lines
7.7 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20152088",
"Version": "oval:org.altlinux.errata:def:20152088",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2015-2088: package `chromium` update to version 47.0.2526.80-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2015-2088",
"RefURL": "https://errata.altlinux.org/ALT-PU-2015-2088",
"Source": "ALTPU"
},
{
"RefID": "BDU:2015-12254",
"RefURL": "https://bdu.fstec.ru/vul/2015-12254",
"Source": "BDU"
},
{
"RefID": "BDU:2015-12255",
"RefURL": "https://bdu.fstec.ru/vul/2015-12255",
"Source": "BDU"
},
{
"RefID": "BDU:2016-00008",
"RefURL": "https://bdu.fstec.ru/vul/2016-00008",
"Source": "BDU"
},
{
"RefID": "BDU:2016-00967",
"RefURL": "https://bdu.fstec.ru/vul/2016-00967",
"Source": "BDU"
},
{
"RefID": "CVE-2015-6788",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6788",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6789",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6789",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6790",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6790",
"Source": "CVE"
},
{
"RefID": "CVE-2015-6791",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2015-6791",
"Source": "CVE"
}
],
"Description": "This update upgrades chromium to version 47.0.2526.80-alt1. \nSecurity Fix(es):\n\n * BDU:2015-12254: Уязвимости браузера Google Chrome, позволяющие нарушителю оказать другое воздействие или вызвать отказ в обслуживании\n\n * BDU:2015-12255: Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие\n\n * BDU:2016-00008: Уязвимость браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании или оказать другое воздействие\n\n * BDU:2016-00967: Уязвимость браузера Google Chrome, позволяющая нарушителю внедрить произвольный Веб- или HTML-код\n\n * CVE-2015-6788: The ObjectBackedNativeHandler class in extensions/renderer/object_backed_native_handler.cc in the extensions subsystem in Google Chrome before 47.0.2526.80 improperly implements handler functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage \"type confusion.\"\n\n * CVE-2015-6789: Race condition in the MutationObserver implementation in Blink, as used in Google Chrome before 47.0.2526.80, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact by leveraging unanticipated object deletion.\n\n * CVE-2015-6790: The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web script or HTML via a crafted document, as demonstrated by a double-quote character inside a single-quoted string.\n\n * CVE-2015-6791: Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.80 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2015-12-10"
},
"Updated": {
"Date": "2015-12-10"
},
"BDUs": [
{
"ID": "BDU:2015-12254",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-17",
"Href": "https://bdu.fstec.ru/vul/2015-12254",
"Impact": "Critical",
"Public": "20151214"
},
{
"ID": "BDU:2015-12255",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "CWE-429",
"Href": "https://bdu.fstec.ru/vul/2015-12255",
"Impact": "Critical",
"Public": "20151214"
},
{
"ID": "BDU:2016-00008",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CWE": "CWE-362",
"Href": "https://bdu.fstec.ru/vul/2016-00008",
"Impact": "Critical",
"Public": "20151214"
},
{
"ID": "BDU:2016-00967",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CWE": "CWE-20",
"Href": "https://bdu.fstec.ru/vul/2016-00967",
"Impact": "Low",
"Public": "20151214"
}
],
"CVEs": [
{
"ID": "CVE-2015-6788",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-Other",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6788",
"Impact": "Critical",
"Public": "20151214"
},
{
"ID": "CVE-2015-6789",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CWE": "CWE-362",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6789",
"Impact": "Critical",
"Public": "20151214"
},
{
"ID": "CVE-2015-6790",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6790",
"Impact": "Low",
"Public": "20151214"
},
{
"ID": "CVE-2015-6791",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2015-6791",
"Impact": "Critical",
"Public": "20151214"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20152088001",
"Comment": "chromium is earlier than 0:47.0.2526.80-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20152088002",
"Comment": "chromium-gnome is earlier than 0:47.0.2526.80-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20152088003",
"Comment": "chromium-kde is earlier than 0:47.0.2526.80-alt1"
}
]
}
]
}
}
]
}