vuln-list-alt/oval/p10/ALT-PU-2021-2827/definitions.json
2024-12-12 21:07:30 +00:00

114 lines
3.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20212827",
"Version": "oval:org.altlinux.errata:def:20212827",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-2827: package `cifs-utils` update to version 6.13-alt3",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit",
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-2827",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2827",
"Source": "ALTPU"
},
{
"RefID": "CVE-2021-20208",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-20208",
"Source": "CVE"
}
],
"Description": "This update upgrades cifs-utils to version 6.13-alt3. \nSecurity Fix(es):\n\n * CVE-2021-20208: A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.\n\n * #40887: Не работает монтирование сетевой папки с помощью pam_mount",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-09-16"
},
"Updated": {
"Date": "2021-09-16"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2021-20208",
"CVSS": "AV:N/AC:M/Au:S/C:P/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N",
"CWE": "CWE-269",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-20208",
"Impact": "Low",
"Public": "20210419"
}
],
"Bugzilla": [
{
"ID": "40887",
"Href": "https://bugzilla.altlinux.org/40887",
"Data": "Не работает монтирование сетевой папки с помощью pam_mount"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:container:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20212827001",
"Comment": "cifs-utils is earlier than 0:6.13-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212827002",
"Comment": "cifs-utils-devel is earlier than 0:6.13-alt3"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212827003",
"Comment": "pam_cifscreds is earlier than 0:6.13-alt3"
}
]
}
]
}
}
]
}