vuln-list-alt/oval/p11/ALT-PU-2018-2448/definitions.json
2024-12-12 21:07:30 +00:00

327 lines
15 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20182448",
"Version": "oval:org.altlinux.errata:def:20182448",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-2448: package `libvirt` update to version 4.8.0-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-2448",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-2448",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-00003",
"RefURL": "https://bdu.fstec.ru/vul/2018-00003",
"Source": "BDU"
},
{
"RefID": "BDU:2018-01492",
"RefURL": "https://bdu.fstec.ru/vul/2018-01492",
"Source": "BDU"
},
{
"RefID": "BDU:2020-00584",
"RefURL": "https://bdu.fstec.ru/vul/2020-00584",
"Source": "BDU"
},
{
"RefID": "BDU:2021-03338",
"RefURL": "https://bdu.fstec.ru/vul/2021-03338",
"Source": "BDU"
},
{
"RefID": "CVE-2017-1000256",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-1000256",
"Source": "CVE"
},
{
"RefID": "CVE-2017-5715",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-5715",
"Source": "CVE"
},
{
"RefID": "CVE-2018-5748",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-5748",
"Source": "CVE"
},
{
"RefID": "CVE-2018-6764",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-6764",
"Source": "CVE"
}
],
"Description": "This update upgrades libvirt to version 4.8.0-alt1. \nSecurity Fix(es):\n\n * BDU:2018-00003: Уязвимость процессоров Intel, ARM и AMD, связанная с особенностями функционирования модуля прогнозирования ветвлений, позволяющая нарушителю получить доступ к защищенной памяти из программы\n\n * BDU:2018-01492: Уязвимость библиотеки управления виртуализацией Libvirt, связанной с ошибкой, приводящей к чрезмерному потреблению памяти, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2020-00584: Уязвимость утилиты util/virlog.c библиотеки управления виртуализацией Libvirt, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2021-03338: Уязвимость библиотеки управления виртуализацией Libvirt, связанная с ошибками процедуры подтверждения подлинности сертификата, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2017-1000256: libvirt version 2.3.0 and later is vulnerable to a bad default configuration of \"verify-peer=no\" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.\n\n * CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.\n\n * CVE-2018-5748: qemu/qemu_monitor.c in libvirt allows attackers to cause a denial of service (memory consumption) via a large QEMU reply.\n\n * CVE-2018-6764: util/virlog.c in libvirt does not properly determine the hostname on LXC container startup, which allows local guest OS users to bypass an intended container protection mechanism and execute arbitrary commands via a crafted NSS module.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-10-09"
},
"Updated": {
"Date": "2018-10-09"
},
"BDUs": [
{
"ID": "BDU:2018-00003",
"CVSS": "AV:L/AC:H/Au:S/C:C/I:N/A:N",
"CVSS3": "AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
"CWE": "CWE-200, CWE-203, CWE-264",
"Href": "https://bdu.fstec.ru/vul/2018-00003",
"Impact": "Low",
"Public": "20180107"
},
{
"ID": "BDU:2018-01492",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"CWE": "CWE-399, CWE-400",
"Href": "https://bdu.fstec.ru/vul/2018-01492",
"Impact": "Low",
"Public": "20180119"
},
{
"ID": "BDU:2020-00584",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"CWE": "CWE-346",
"Href": "https://bdu.fstec.ru/vul/2020-00584",
"Impact": "Low",
"Public": "20180207"
},
{
"ID": "BDU:2021-03338",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-295",
"Href": "https://bdu.fstec.ru/vul/2021-03338",
"Impact": "High",
"Public": "20171005"
}
],
"CVEs": [
{
"ID": "CVE-2017-1000256",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-295",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-1000256",
"Impact": "High",
"Public": "20171031"
},
{
"ID": "CVE-2017-5715",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
"CWE": "CWE-203",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-5715",
"Impact": "Low",
"Public": "20180104"
},
{
"ID": "CVE-2018-5748",
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-5748",
"Impact": "High",
"Public": "20180125"
},
{
"ID": "CVE-2018-6764",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-346",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-6764",
"Impact": "High",
"Public": "20180223"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20182448001",
"Comment": "libvirt is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448002",
"Comment": "libvirt-admin is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448003",
"Comment": "libvirt-client is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448004",
"Comment": "libvirt-daemon is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448005",
"Comment": "libvirt-daemon-config-network is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448006",
"Comment": "libvirt-daemon-config-nwfilter is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448007",
"Comment": "libvirt-daemon-driver-interface is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448008",
"Comment": "libvirt-daemon-driver-lxc is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448009",
"Comment": "libvirt-daemon-driver-network is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448010",
"Comment": "libvirt-daemon-driver-nodedev is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448011",
"Comment": "libvirt-daemon-driver-nwfilter is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448012",
"Comment": "libvirt-daemon-driver-qemu is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448013",
"Comment": "libvirt-daemon-driver-secret is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448014",
"Comment": "libvirt-daemon-driver-storage is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448015",
"Comment": "libvirt-daemon-driver-storage-core is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448016",
"Comment": "libvirt-daemon-driver-storage-disk is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448017",
"Comment": "libvirt-daemon-driver-storage-fs is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448018",
"Comment": "libvirt-daemon-driver-storage-gluster is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448019",
"Comment": "libvirt-daemon-driver-storage-iscsi is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448020",
"Comment": "libvirt-daemon-driver-storage-iscsi-direct is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448021",
"Comment": "libvirt-daemon-driver-storage-logical is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448022",
"Comment": "libvirt-daemon-driver-storage-mpath is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448023",
"Comment": "libvirt-daemon-driver-storage-rbd is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448024",
"Comment": "libvirt-daemon-driver-storage-scsi is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448025",
"Comment": "libvirt-daemon-driver-storage-zfs is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448026",
"Comment": "libvirt-daemon-driver-vbox is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448027",
"Comment": "libvirt-devel is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448028",
"Comment": "libvirt-docs is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448029",
"Comment": "libvirt-kvm is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448030",
"Comment": "libvirt-libs is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448031",
"Comment": "libvirt-lock-sanlock is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448032",
"Comment": "libvirt-login-shell is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448033",
"Comment": "libvirt-lxc is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448034",
"Comment": "libvirt-qemu is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448035",
"Comment": "libvirt-qemu-common is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448036",
"Comment": "libvirt-vbox is earlier than 0:4.8.0-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20182448037",
"Comment": "nss-libvirt is earlier than 0:4.8.0-alt1"
}
]
}
]
}
}
]
}