2024-06-28 13:17:52 +00:00

229 lines
9.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172680",
"Version": "oval:org.altlinux.errata:def:20172680",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2680: package `samba-DC` update to version 4.6.11-alt1.S1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2680",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2680",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-01422",
"RefURL": "https://bdu.fstec.ru/vul/2021-01422",
"Source": "BDU"
},
{
"RefID": "BDU:2021-01435",
"RefURL": "https://bdu.fstec.ru/vul/2021-01435",
"Source": "BDU"
},
{
"RefID": "CVE-2017-14746",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-14746",
"Source": "CVE"
},
{
"RefID": "CVE-2017-15275",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-15275",
"Source": "CVE"
}
],
"Description": "This update upgrades samba-DC to version 4.6.11-alt1.S1. \nSecurity Fix(es):\n\n * BDU:2021-01422: Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2021-01435: Уязвимость пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным\n\n * CVE-2017-14746: Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.\n\n * CVE-2017-15275: Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-11-21"
},
"Updated": {
"Date": "2017-11-21"
},
"BDUs": [
{
"ID": "BDU:2021-01422",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2021-01422",
"Impact": "Critical",
"Public": "20171127"
},
{
"ID": "BDU:2021-01435",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2021-01435",
"Impact": "High",
"Public": "20171127"
}
],
"CVEs": [
{
"ID": "CVE-2017-14746",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-14746",
"Impact": "Critical",
"Public": "20171127"
},
{
"ID": "CVE-2017-15275",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-15275",
"Impact": "High",
"Public": "20171127"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172680001",
"Comment": "libldb-modules-DC is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680002",
"Comment": "libwbclient-DC is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680003",
"Comment": "libwbclient-DC-devel is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680004",
"Comment": "python-module-samba-DC is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680005",
"Comment": "samba-DC is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680006",
"Comment": "samba-DC-client is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680007",
"Comment": "samba-DC-common is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680008",
"Comment": "samba-DC-common-libs is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680009",
"Comment": "samba-DC-ctdb is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680010",
"Comment": "samba-DC-ctdb-tests is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680011",
"Comment": "samba-DC-devel is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680012",
"Comment": "samba-DC-doc is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680013",
"Comment": "samba-DC-libs is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680014",
"Comment": "samba-DC-pidl is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680015",
"Comment": "samba-DC-test is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680016",
"Comment": "samba-DC-util-private-headers is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680017",
"Comment": "samba-DC-winbind is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680018",
"Comment": "samba-DC-winbind-clients is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680019",
"Comment": "samba-DC-winbind-krb5-locator is earlier than 0:4.6.11-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172680020",
"Comment": "task-samba-dc is earlier than 0:4.6.11-alt1.S1"
}
]
}
]
}
}
]
}