vuln-list-alt/oval/p9/ALT-PU-2020-3401/definitions.json
2024-12-12 21:07:30 +00:00

205 lines
8.9 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20203401",
"Version": "oval:org.altlinux.errata:def:20203401",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-3401: package `glibc` update to version 2.27-alt13",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-3401",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-3401",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-03566",
"RefURL": "https://bdu.fstec.ru/vul/2020-03566",
"Source": "BDU"
},
{
"RefID": "BDU:2021-03122",
"RefURL": "https://bdu.fstec.ru/vul/2021-03122",
"Source": "BDU"
},
{
"RefID": "CVE-2020-1752",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-1752",
"Source": "CVE"
},
{
"RefID": "CVE-2020-6096",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-6096",
"Source": "CVE"
}
],
"Description": "This update upgrades glibc to version 2.27-alt13. \nSecurity Fix(es):\n\n * BDU:2020-03566: Уязвимость функции memcpy библиотеки glibc, позволяющая нарушителю выполнить произвольный код в контексте привилегированного процесса\n\n * BDU:2021-03122: Уязвимость функции glob библиотеки glibc операционной системы Аврора, связанная с использованием памяти после ее освобождения, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код\n\n * CVE-2020-1752: A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32.\n\n * CVE-2020-6096: An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-11-23"
},
"Updated": {
"Date": "2020-11-23"
},
"BDUs": [
{
"ID": "BDU:2020-03566",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-191",
"Href": "https://bdu.fstec.ru/vul/2020-03566",
"Impact": "High",
"Public": "20200401"
},
{
"ID": "BDU:2021-03122",
"CVSS": "AV:L/AC:H/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2021-03122",
"Impact": "High",
"Public": "20210616"
}
],
"CVEs": [
{
"ID": "CVE-2020-1752",
"CVSS": "AV:L/AC:H/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-1752",
"Impact": "High",
"Public": "20200430"
},
{
"ID": "CVE-2020-6096",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-6096",
"Impact": "High",
"Public": "20200401"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20203401001",
"Comment": "glibc is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401002",
"Comment": "glibc-core is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401003",
"Comment": "glibc-debug is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401004",
"Comment": "glibc-devel is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401005",
"Comment": "glibc-devel-static is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401006",
"Comment": "glibc-doc is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401007",
"Comment": "glibc-gconv-modules is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401008",
"Comment": "glibc-i18ndata is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401009",
"Comment": "glibc-locales is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401010",
"Comment": "glibc-nss is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401011",
"Comment": "glibc-preinstall is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401012",
"Comment": "glibc-pthread is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401013",
"Comment": "glibc-source is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401014",
"Comment": "glibc-timezones is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401015",
"Comment": "glibc-utils is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401016",
"Comment": "iconv is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401017",
"Comment": "libnsl1 is earlier than 6:2.27-alt13"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203401018",
"Comment": "nscd is earlier than 6:2.27-alt13"
}
]
}
]
}
}
]
}