102 lines
3.6 KiB
JSON
102 lines
3.6 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20171610",
|
|
"Version": "oval:org.altlinux.errata:def:20171610",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2017-1610: package `php7` update to version 7.1.5-alt1.S1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch c9f2"
|
|
],
|
|
"Products": [
|
|
"ALT SPWorkstation",
|
|
"ALT SPServer"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2017-1610",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-1610",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2017-7963",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-7963",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades php7 to version 7.1.5-alt1.S1. \nSecurity Fix(es):\n\n * CVE-2017-7963: The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating \"There is no security issue here, because GMP safely aborts in case of an OOM condition. The only attack vector here is denial of service. However, if you allow attacker-controlled, unbounded allocations you have a DoS vector regardless of GMP's OOM behavior.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "High",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2017-05-15"
|
|
},
|
|
"Updated": {
|
|
"Date": "2017-05-15"
|
|
},
|
|
"BDUs": null,
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2017-7963",
|
|
"CVSS": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
|
"CWE": "CWE-770",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-7963",
|
|
"Impact": "High",
|
|
"Public": "20170419"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:spworkstation:8.4",
|
|
"cpe:/o:alt:spserver:8.4"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:3001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171610001",
|
|
"Comment": "php7 is earlier than 0:7.1.5-alt1.S1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171610002",
|
|
"Comment": "php7-devel is earlier than 0:7.1.5-alt1.S1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171610003",
|
|
"Comment": "php7-libs is earlier than 0:7.1.5-alt1.S1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171610004",
|
|
"Comment": "php7-mysqlnd is earlier than 0:7.1.5-alt1.S1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171610005",
|
|
"Comment": "rpm-build-php7-version is earlier than 0:7.1.5-alt1.S1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |