2024-06-28 13:17:52 +00:00

156 lines
5.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20181998",
"Version": "oval:org.altlinux.errata:def:20181998",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-1998: package `libspice-gtk` update to version 0.35-alt1.S1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-1998",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-1998",
"Source": "ALTPU"
},
{
"RefID": "BDU:2018-00589",
"RefURL": "https://bdu.fstec.ru/vul/2018-00589",
"Source": "BDU"
},
{
"RefID": "CVE-2017-12194",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-12194",
"Source": "CVE"
}
],
"Description": "This update upgrades libspice-gtk to version 0.35-alt1.S1. \nSecurity Fix(es):\n\n * BDU:2018-00589: Уязвимость SPICE-клиента Spice-GTK, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код\n\n * CVE-2017-12194: A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-07-11"
},
"Updated": {
"Date": "2018-07-11"
},
"BDUs": [
{
"ID": "BDU:2018-00589",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CWE": "CWE-20",
"Href": "https://bdu.fstec.ru/vul/2018-00589",
"Impact": "High",
"Public": "20180314"
}
],
"CVEs": [
{
"ID": "CVE-2017-12194",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-20",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-12194",
"Impact": "Critical",
"Public": "20180314"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20181998001",
"Comment": "libspice-glib is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998002",
"Comment": "libspice-glib-devel is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998003",
"Comment": "libspice-glib-gir is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998004",
"Comment": "libspice-glib-gir-devel is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998005",
"Comment": "libspice-gtk-tools is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998006",
"Comment": "libspice-gtk3 is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998007",
"Comment": "libspice-gtk3-devel is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998008",
"Comment": "libspice-gtk3-gir is earlier than 0:0.35-alt1.S1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181998009",
"Comment": "libspice-gtk3-gir-devel is earlier than 0:0.35-alt1.S1"
}
]
}
]
}
}
]
}