vuln-list-alt/oval/p11/ALT-PU-2020-2539/definitions.json
2024-12-12 21:07:30 +00:00

151 lines
6.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20202539",
"Version": "oval:org.altlinux.errata:def:20202539",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-2539: package `postgresql11-1C` update to version 11.9-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-2539",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-2539",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-00079",
"RefURL": "https://bdu.fstec.ru/vul/2021-00079",
"Source": "BDU"
},
{
"RefID": "BDU:2023-00613",
"RefURL": "https://bdu.fstec.ru/vul/2023-00613",
"Source": "BDU"
},
{
"RefID": "CVE-2020-14349",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-14349",
"Source": "CVE"
},
{
"RefID": "CVE-2020-14350",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-14350",
"Source": "CVE"
}
],
"Description": "This update upgrades postgresql11-1C to version 11.9-alt1. \nSecurity Fix(es):\n\n * BDU:2021-00079: Уязвимость системы управления базами данных PostgreSQL, связанная с ненадежным путем поиска, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2023-00613: Уязвимость системы управления базами данных PostgreSQL, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю повысить свои привилегии и выполнить произвольные команды\n\n * CVE-2020-14349: It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to execute arbitrary SQL command in the context of the user used for replication.\n\n * CVE-2020-14350: It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-08-12"
},
"Updated": {
"Date": "2020-08-12"
},
"BDUs": [
{
"ID": "BDU:2021-00079",
"CVSS": "AV:L/AC:M/Au:S/C:C/I:C/A:C",
"CVSS3": "AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-426",
"Href": "https://bdu.fstec.ru/vul/2021-00079",
"Impact": "High",
"Public": "20200824"
},
{
"ID": "BDU:2023-00613",
"CVSS": "AV:N/AC:H/Au:S/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-20, CWE-89, CWE-427",
"Href": "https://bdu.fstec.ru/vul/2023-00613",
"Impact": "High",
"Public": "20200617"
}
],
"CVEs": [
{
"ID": "CVE-2020-14349",
"CVSS": "AV:N/AC:H/Au:S/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-89",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-14349",
"Impact": "High",
"Public": "20200824"
},
{
"ID": "CVE-2020-14350",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-426",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-14350",
"Impact": "High",
"Public": "20200824"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20202539001",
"Comment": "postgresql11-1C is earlier than 0:11.9-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202539002",
"Comment": "postgresql11-1C-contrib is earlier than 0:11.9-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202539003",
"Comment": "postgresql11-1C-docs is earlier than 0:11.9-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202539004",
"Comment": "postgresql11-1C-perl is earlier than 0:11.9-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202539005",
"Comment": "postgresql11-1C-python is earlier than 0:11.9-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202539006",
"Comment": "postgresql11-1C-server is earlier than 0:11.9-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20202539007",
"Comment": "postgresql11-1C-tcl is earlier than 0:11.9-alt1"
}
]
}
]
}
}
]
}