vuln-list-alt/oval/c10f1/ALT-PU-2021-1058/definitions.json
2024-06-28 13:17:52 +00:00

129 lines
5.1 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20211058",
"Version": "oval:org.altlinux.errata:def:20211058",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-1058: package `edk2-aarch64` update to version 20201127-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-1058",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-1058",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-00267",
"RefURL": "https://bdu.fstec.ru/vul/2022-00267",
"Source": "BDU"
},
{
"RefID": "BDU:2022-01653",
"RefURL": "https://bdu.fstec.ru/vul/2022-01653",
"Source": "BDU"
},
{
"RefID": "CVE-2019-11098",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-11098",
"Source": "CVE"
},
{
"RefID": "CVE-2019-14584",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-14584",
"Source": "CVE"
}
],
"Description": "This update upgrades edk2-aarch64 to version 20201127-alt1. \nSecurity Fix(es):\n\n * BDU:2022-00267: Уязвимость среды с открытым исходным кодом для разработки UEFI edk2, связанная с ошибками разыменования указателя, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2022-01653: Уязвимость компонента MdeModulePkg среды с открытым исходным кодом для разработки UEFI EDK2, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2019-11098: Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.\n\n * CVE-2019-14584: Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-01-19"
},
"Updated": {
"Date": "2021-01-19"
},
"BDUs": [
{
"ID": "BDU:2022-00267",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-476",
"Href": "https://bdu.fstec.ru/vul/2022-00267",
"Impact": "High",
"Public": "20201213"
},
{
"ID": "BDU:2022-01653",
"CVSS": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-20",
"Href": "https://bdu.fstec.ru/vul/2022-01653",
"Impact": "Low",
"Public": "20190312"
}
],
"CVEs": [
{
"ID": "CVE-2019-11098",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-11098",
"Impact": "Low",
"Public": "20210714"
},
{
"ID": "CVE-2019-14584",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-476",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-14584",
"Impact": "High",
"Public": "20210603"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20211058001",
"Comment": "edk2-aarch64 is earlier than 0:20201127-alt1"
}
]
}
]
}
}
]
}