vuln-list-alt/oval/c10f1/ALT-PU-2021-4842/definitions.json
2024-06-28 13:17:52 +00:00

129 lines
5.6 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20214842",
"Version": "oval:org.altlinux.errata:def:20214842",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-4842: package `docker-engine` update to version 20.10.3-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-4842",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-4842",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-01892",
"RefURL": "https://bdu.fstec.ru/vul/2021-01892",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01893",
"RefURL": "https://bdu.fstec.ru/vul/2021-01893",
"Source": "BDU"
},
{
"RefID": "CVE-2021-21284",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-21284",
"Source": "CVE"
},
{
"RefID": "CVE-2021-21285",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-21285",
"Source": "CVE"
}
],
"Description": "This update upgrades docker-engine to version 20.10.3-alt1. \nSecurity Fix(es):\n\n * BDU:2021-01892: Уязвимость демона dockerd средства автоматизации развёртывания и управления приложениями в средах с поддержкой контейнеризации Docker, связанная с ошибкой механизма контроля расходуемых ресурсов, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-01893: Уязвимость опции --userns-remap средства автоматизации развёртывания и управления приложениями в средах с поддержкой контейнеризации Docker, связанная с некорректным ограничением имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность данных\n\n * CVE-2021-21284: In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using \"--userns-remap\", if the root user in the remapped namespace has access to the host filesystem they can modify files under \"/var/lib/docker/\u003cremapping\u003e\" that cause writing files with extended privileges. Versions 20.10.3 and 19.03.15 contain patches that prevent privilege escalation from remapped user.\n\n * CVE-2021-21285: In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-04-04"
},
"Updated": {
"Date": "2024-04-04"
},
"BDUs": [
{
"ID": "BDU:2021-01892",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-400",
"Href": "https://bdu.fstec.ru/vul/2021-01892",
"Impact": "Low",
"Public": "20201222"
},
{
"ID": "BDU:2021-01893",
"CVSS": "AV:A/AC:L/Au:S/C:N/I:P/A:N",
"CVSS3": "AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2021-01893",
"Impact": "Low",
"Public": "20201222"
}
],
"CVEs": [
{
"ID": "CVE-2021-21284",
"CVSS": "AV:A/AC:L/Au:S/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-21284",
"Impact": "Low",
"Public": "20210202"
},
{
"ID": "CVE-2021-21285",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-754",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-21285",
"Impact": "Low",
"Public": "20210202"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20214842001",
"Comment": "docker-engine is earlier than 0:20.10.3-alt1"
}
]
}
]
}
}
]
}