vuln-list-alt/oval/p9/ALT-PU-2017-2150/definitions.json
2024-12-12 21:07:30 +00:00

171 lines
7.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20172150",
"Version": "oval:org.altlinux.errata:def:20172150",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2017-2150: package `shadow` update to version 4.5-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2017-2150",
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-2150",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-05844",
"RefURL": "https://bdu.fstec.ru/vul/2021-05844",
"Source": "BDU"
},
{
"RefID": "BDU:2021-05845",
"RefURL": "https://bdu.fstec.ru/vul/2021-05845",
"Source": "BDU"
},
{
"RefID": "CVE-2017-12424",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-12424",
"Source": "CVE"
},
{
"RefID": "CVE-2017-20002",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2017-20002",
"Source": "CVE"
}
],
"Description": "This update upgrades shadow to version 4.5-alt1. \nSecurity Fix(es):\n\n * BDU:2021-05844: Уязвимость инструмента newusers утилиты для управления учетными записями shadow, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * BDU:2021-05845: Уязвимость утилиты для управления учетными записями shadow, связанная с небезопасным управлением привилегиями, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании\n\n * CVE-2017-12424: In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.\n\n * CVE-2017-20002: The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local users to login as password-less users even if they are connected by non-physical means such as SSH (hence bypassing PAM's nullok_secure configuration). This notably affects environments such as virtual machines automatically generated with a default blank root password, allowing all local users to escalate privileges.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2017-09-06"
},
"Updated": {
"Date": "2017-09-06"
},
"BDUs": [
{
"ID": "BDU:2021-05844",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2021-05844",
"Impact": "Critical",
"Public": "20140731"
},
{
"ID": "BDU:2021-05845",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-269",
"Href": "https://bdu.fstec.ru/vul/2021-05845",
"Impact": "High",
"Public": "20181129"
}
],
"CVEs": [
{
"ID": "CVE-2017-12424",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-119",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-12424",
"Impact": "Critical",
"Public": "20170804"
},
{
"ID": "CVE-2017-20002",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-269",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2017-20002",
"Impact": "High",
"Public": "20210317"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20172150001",
"Comment": "shadow-change is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150002",
"Comment": "shadow-check is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150003",
"Comment": "shadow-convert is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150004",
"Comment": "shadow-edit is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150005",
"Comment": "shadow-groups is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150006",
"Comment": "shadow-log is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150007",
"Comment": "shadow-submap is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150008",
"Comment": "shadow-suite is earlier than 1:4.5-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20172150009",
"Comment": "shadow-utils is earlier than 1:4.5-alt1"
}
]
}
]
}
}
]
}