vuln-list-alt/oval/c10f1/ALT-PU-2024-15240/definitions.json
2024-11-13 03:04:50 +00:00

124 lines
4.7 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:202415240",
"Version": "oval:org.altlinux.errata:def:202415240",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-15240: package `p7zip` update to version 17.05-alt3",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-15240",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-15240",
"Source": "ALTPU"
},
{
"RefID": "BDU:2024-04975",
"RefURL": "https://bdu.fstec.ru/vul/2024-04975",
"Source": "BDU"
},
{
"RefID": "CVE-2023-52168",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-52168",
"Source": "CVE"
},
{
"RefID": "CVE-2023-52169",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-52169",
"Source": "CVE"
}
],
"Description": "This update upgrades p7zip to version 17.05-alt3. \nSecurity Fix(es):\n\n * BDU:2024-04975: Уязвимость обработчика NTFS в файле NtfsHandler.cpp архиватора 7-Zip, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2023-52168: The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple offsets beyond the allocated buffer size: buffer+512*i-2, for i=9, i=10, i=11, etc.\n\n * CVE-2023-52169: The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The bytes read beyond the intended buffer are presented as a part of a filename listed in the file system image. This has security relevance in some known web-service use cases where untrusted users can upload files and have them extracted by a server-side 7-Zip process.\n\n * #45641: При распаковке zip архива сообщает об уже существующем файле",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-11-12"
},
"Updated": {
"Date": "2024-11-12"
},
"BDUs": [
{
"ID": "BDU:2024-04975",
"CVSS": "AV:N/AC:H/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"CWE": "CWE-122",
"Href": "https://bdu.fstec.ru/vul/2024-04975",
"Impact": "Critical",
"Public": "20240703"
}
],
"CVEs": [
{
"ID": "CVE-2023-52168",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-52168",
"Impact": "None",
"Public": "20240703"
},
{
"ID": "CVE-2023-52169",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-52169",
"Impact": "None",
"Public": "20240703"
}
],
"Bugzilla": [
{
"ID": "45641",
"Href": "https://bugzilla.altlinux.org/45641",
"Data": "При распаковке zip архива сообщает об уже существующем файле"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:202415240001",
"Comment": "p7zip is earlier than 0:17.05-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:202415240002",
"Comment": "p7zip-devel is earlier than 0:17.05-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:202415240003",
"Comment": "p7zip-standalone is earlier than 0:17.05-alt3"
}
]
}
]
}
}
]
}