2024-04-16 14:26:14 +00:00

144 lines
5.5 KiB
JSON

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20211405",
"Version": "oval:org.altlinux.errata:def:20211405",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-1405: package `alsa-utils` update to version 1.2.4-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-1405",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-1405",
"Source": "ALTPU"
},
{
"RefID": "CVE-2009-0035",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2009-0035",
"Source": "CVE"
},
{
"RefID": "CVE-2019-13351",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-13351",
"Source": "CVE"
}
],
"Description": "This update upgrades alsa-utils to version 1.2.4-alt1. \nSecurity Fix(es):\n\n * CVE-2009-0035: alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.\n\n * CVE-2019-13351: posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a \"double file descriptor close\" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.\n\n * #37757: Снова ошибка - alsactl: sysfs_init:48: sysfs path '/sys' is invalid\n\n * #38416: [FR] дополнить alsa-info.sh сводкой информации по установленным пакетам alsa",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-02-25"
},
"Updated": {
"Date": "2024-04-04"
},
"BDUs": null,
"CVEs": [
{
"ID": "CVE-2009-0035",
"CVSS": "AV:L/AC:L/Au:N/C:N/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"CWE": "CWE-59",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2009-0035",
"Impact": "Low",
"Public": "20191109"
},
{
"ID": "CVE-2019-13351",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"CWE": "NVD-CWE-noinfo",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-13351",
"Impact": "High",
"Public": "20190705"
}
],
"Bugzilla": [
{
"ID": "37757",
"Href": "https://bugzilla.altlinux.org/37757",
"Data": "Снова ошибка - alsactl: sysfs_init:48: sysfs path '/sys' is invalid"
},
{
"ID": "38416",
"Href": "https://bugzilla.altlinux.org/38416",
"Data": "[FR] дополнить alsa-info.sh сводкой информации по установленным пакетам alsa"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20211405001",
"Comment": "alsa-utils is earlier than 1:1.2.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20211405002",
"Comment": "amixer is earlier than 1:1.2.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20211405003",
"Comment": "aplay is earlier than 1:1.2.4-alt1"
}
]
}
]
}
}
]
}