vuln-list-alt/oval/c9f2/ALT-PU-2023-1283/definitions.json
2024-04-16 14:26:14 +00:00

164 lines
6.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20231283",
"Version": "oval:org.altlinux.errata:def:20231283",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2023-1283: package `NetworkManager` update to version 1.18.11-alt1.gite2fdbc2b7482",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c9f2"
],
"Products": [
"ALT SPWorkstation",
"ALT SPServer"
]
}
],
"References": [
{
"RefID": "ALT-PU-2023-1283",
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-1283",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-06889",
"RefURL": "https://bdu.fstec.ru/vul/2022-06889",
"Source": "BDU"
},
{
"RefID": "CVE-2020-13529",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-13529",
"Source": "CVE"
}
],
"Description": "This update upgrades NetworkManager to version 1.18.11-alt1.gite2fdbc2b7482. \nSecurity Fix(es):\n\n * BDU:2022-06889: Уязвимость подсистемы инициализации и управления службами Systemd, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2020-13529: An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.\n\n * #39997: Альт Рабочая станция К (p9) постоянно запрашивает пароль wifi/не запоминает сеть (кривая поддержка WPA3)",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2023-02-17"
},
"Updated": {
"Date": "2023-02-17"
},
"BDUs": [
{
"ID": "BDU:2022-06889",
"CVSS": "AV:A/AC:M/Au:N/C:N/I:N/A:C",
"CVSS3": "AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H",
"CWE": "CWE-290",
"Href": "https://bdu.fstec.ru/vul/2022-06889",
"Impact": "Low",
"Public": "20200818"
}
],
"CVEs": [
{
"ID": "CVE-2020-13529",
"CVSS": "AV:A/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H",
"CWE": "CWE-290",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-13529",
"Impact": "Low",
"Public": "20210510"
}
],
"Bugzilla": [
{
"ID": "39997",
"Href": "https://bugzilla.altlinux.org/39997",
"Data": "Альт Рабочая станция К (p9) постоянно запрашивает пароль wifi/не запоминает сеть (кривая поддержка WPA3)"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:8.4",
"cpe:/o:alt:spserver:8.4"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20231283001",
"Comment": "NetworkManager is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283002",
"Comment": "NetworkManager-adsl is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283003",
"Comment": "NetworkManager-bluetooth is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283004",
"Comment": "NetworkManager-daemon is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283005",
"Comment": "NetworkManager-ovs is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283006",
"Comment": "NetworkManager-ppp is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283007",
"Comment": "NetworkManager-team is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283008",
"Comment": "NetworkManager-tui is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283009",
"Comment": "NetworkManager-wifi is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283010",
"Comment": "NetworkManager-wwan is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283011",
"Comment": "libnm is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283012",
"Comment": "libnm-devel is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283013",
"Comment": "libnm-devel-doc is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283014",
"Comment": "libnm-gir is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231283015",
"Comment": "libnm-gir-devel is earlier than 0:1.18.11-alt1.gite2fdbc2b7482"
}
]
}
]
}
}
]
}