473 lines
25 KiB
JSON
473 lines
25 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20171049",
|
|
"Version": "oval:org.altlinux.errata:def:20171049",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2017-1049: package `libwebkitgtk4` update to version 2.14.3-alt1",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch p10"
|
|
],
|
|
"Products": [
|
|
"ALT Server",
|
|
"ALT Virtualization Server",
|
|
"ALT Workstation",
|
|
"ALT Workstation K",
|
|
"ALT Education",
|
|
"Simply Linux",
|
|
"Starterkit",
|
|
"ALT Container"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2017-1049",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2017-1049",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00394",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00394",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00400",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00400",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00404",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00404",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00406",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00406",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00410",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00410",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00413",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00413",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00467",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00467",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00469",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00469",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00478",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00478",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00484",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00484",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00486",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00486",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00489",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00489",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2017-00497",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2017-00497",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7586",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7586",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7589",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7589",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7592",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7592",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7599",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7599",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7623",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7623",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7632",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7632",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7635",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7635",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7639",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7639",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7641",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7641",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7645",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7645",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7652",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7652",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7654",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7654",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2016-7656",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2016-7656",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades libwebkitgtk4 to version 2.14.3-alt1. \nSecurity Fix(es):\n\n * BDU:2017-00394: Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes, браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00400: Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes, браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00404: Уязвимость браузера Safari, операционной системы iOS, мультимедийного проигрывателя iTunes, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00406: Уязвимость браузера Safari, операционной системы iOS, мультимедийного проигрывателя iTunes, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00410: Уязвимость браузера Safari, мультимедийного проигрывателя iTunes, операционной системы iOS, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00413: Уязвимость мультимедийного проигрывателя iTunes, операционной системы iOS, браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00467: Уязвимость браузера Safari, мультимедийного проигрывателя iTunes, операционной системы iOS, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2017-00469: Уязвимость браузера Safari, мультимедийного проигрывателя iTunes, операционной системы iOS, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании\n\n * BDU:2017-00478: Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari, позволяющая нарушителю получить конфиденциальную информацию или обойти существующую политику ограничения доступа\n\n * BDU:2017-00484: Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari , позволяющая нарушителю получить конфиденциальную информацию\n\n * BDU:2017-00486: Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код\n\n * BDU:2017-00489: Уязвимость операционной системы iOS, мультимедийного проигрывателя iTunes и браузера Safari, позволяющая нарушителю получить конфиденциальную информацию\n\n * BDU:2017-00497: Уязвимость браузера Safari и операционной системы iOS, позволяющая нарушителю получить конфиденциальную информацию\n\n * CVE-2016-7586: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to obtain sensitive information via a crafted web site.\n\n * CVE-2016-7589: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. watchOS before 3.1.3 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7592: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component, which allows remote attackers to obtain sensitive information via crafted JavaScript prompts on a web site.\n\n * CVE-2016-7599: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site that uses HTTP redirects.\n\n * CVE-2016-7623: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to obtain sensitive information via a blob URL on a web site.\n\n * CVE-2016-7632: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7635: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7639: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7641: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7645: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7652: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7654: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.\n\n * CVE-2016-7656: An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the \"WebKit\" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "High",
|
|
"Rights": "Copyright 2024 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2017-01-18"
|
|
},
|
|
"Updated": {
|
|
"Date": "2017-01-18"
|
|
},
|
|
"BDUs": [
|
|
{
|
|
"ID": "BDU:2017-00394",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00394",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00400",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00400",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00404",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00404",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00406",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00406",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00410",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00410",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00413",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00413",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00467",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00467",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00469",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00469",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00478",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00478",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00484",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00484",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00486",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00486",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00489",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00489",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "BDU:2017-00497",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://bdu.fstec.ru/vul/2017-00497",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
}
|
|
],
|
|
"CVEs": [
|
|
{
|
|
"ID": "CVE-2016-7586",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7586",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7589",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7589",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7592",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7592",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7599",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7599",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7623",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
|
|
"CWE": "CWE-200",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7623",
|
|
"Impact": "Low",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7632",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7632",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7635",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7635",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7639",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7639",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7641",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7641",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7645",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7645",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7652",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7652",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7654",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7654",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
},
|
|
{
|
|
"ID": "CVE-2016-7656",
|
|
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
|
|
"CVSS3": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
|
|
"CWE": "CWE-119",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2016-7656",
|
|
"Impact": "High",
|
|
"Public": "20170220"
|
|
}
|
|
],
|
|
"AffectedCPEs": {
|
|
"CPEs": [
|
|
"cpe:/o:alt:kworkstation:10",
|
|
"cpe:/o:alt:workstation:10",
|
|
"cpe:/o:alt:server:10",
|
|
"cpe:/o:alt:server-v:10",
|
|
"cpe:/o:alt:education:10",
|
|
"cpe:/o:alt:slinux:10",
|
|
"cpe:/o:alt:starterkit:10",
|
|
"cpe:/o:alt:starterkit:p10",
|
|
"cpe:/o:alt:container:10"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:2001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049001",
|
|
"Comment": "jsc4 is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049002",
|
|
"Comment": "libjavascriptcoregtk4 is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049003",
|
|
"Comment": "libjavascriptcoregtk4-devel is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049004",
|
|
"Comment": "libjavascriptcoregtk4-gir is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049005",
|
|
"Comment": "libjavascriptcoregtk4-gir-devel is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049006",
|
|
"Comment": "libwebkit2gtk is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049007",
|
|
"Comment": "libwebkit2gtk-devel is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049008",
|
|
"Comment": "libwebkit2gtk-gir is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049009",
|
|
"Comment": "libwebkit2gtk-gir-devel is earlier than 0:2.14.3-alt1"
|
|
},
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20171049010",
|
|
"Comment": "webkitgtk-minibrowser is earlier than 0:2.14.3-alt1"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |