153 lines
6.1 KiB
JSON
153 lines
6.1 KiB
JSON
{
|
|
"Definition": [
|
|
{
|
|
"ID": "oval:org.altlinux.errata:def:20212819",
|
|
"Version": "oval:org.altlinux.errata:def:20212819",
|
|
"Class": "patch",
|
|
"Metadata": {
|
|
"Title": "ALT-PU-2021-2819: package `php7-opcache` update to version 7.3.30-alt1.3",
|
|
"AffectedList": [
|
|
{
|
|
"Family": "unix",
|
|
"Platforms": [
|
|
"ALT Linux branch p9"
|
|
],
|
|
"Products": [
|
|
"ALT Server",
|
|
"ALT Virtualization Server",
|
|
"ALT Workstation",
|
|
"ALT Workstation K",
|
|
"ALT Education",
|
|
"Simply Linux",
|
|
"Starterkit"
|
|
]
|
|
}
|
|
],
|
|
"References": [
|
|
{
|
|
"RefID": "ALT-PU-2021-2819",
|
|
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2819",
|
|
"Source": "ALTPU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2021-03559",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2021-03559",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "BDU:2021-03703",
|
|
"RefURL": "https://bdu.fstec.ru/vul/2021-03703",
|
|
"Source": "BDU"
|
|
},
|
|
{
|
|
"RefID": "CVE-2021-21704",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-21704",
|
|
"Source": "CVE"
|
|
},
|
|
{
|
|
"RefID": "CVE-2021-21705",
|
|
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-21705",
|
|
"Source": "CVE"
|
|
}
|
|
],
|
|
"Description": "This update upgrades php7-opcache to version 7.3.30-alt1.3. \nSecurity Fix(es):\n\n * BDU:2021-03559: Уязвимость модуля pdo_firebase интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2021-03703: Уязвимость функции php_url_parse_ex() интерпретатора языка программирования PHP, позволяющая нарушителю осуществить SSRF-атаку\n\n * CVE-2021-21704: In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using Firebird PDO driver extension, a malicious database server could cause crashes in various database functions, such as getAttribute(), execute(), fetch() and others by returning invalid response data that is not parsed correctly by the driver. This can result in crashes, denial of service or potentially memory corruption.\n\n * CVE-2021-21705: In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.",
|
|
"Advisory": {
|
|
"From": "errata.altlinux.org",
|
|
"Severity": "Low",
|
|
"Rights": "Copyright 2023 BaseALT Ltd.",
|
|
"Issued": {
|
|
"Date": "2021-09-16"
|
|
},
|
|
"Updated": {
|
|
"Date": "2021-09-16"
|
|
},
|
|
"bdu": [
|
|
{
|
|
"Cvss": "AV:N/AC:H/Au:N/C:N/I:N/A:C",
|
|
"Cvss3": "AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
|
"Cwe": "CWE-20",
|
|
"Href": "https://bdu.fstec.ru/vul/2021-03559",
|
|
"Impact": "Low",
|
|
"Public": "20210629",
|
|
"CveID": "BDU:2021-03559"
|
|
},
|
|
{
|
|
"Cvss": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
|
|
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
|
"Cwe": "CWE-20, CWE-918",
|
|
"Href": "https://bdu.fstec.ru/vul/2021-03703",
|
|
"Impact": "Low",
|
|
"Public": "20210702",
|
|
"CveID": "BDU:2021-03703"
|
|
}
|
|
],
|
|
"Cves": [
|
|
{
|
|
"Cvss": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
|
|
"Cvss3": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
|
|
"Cwe": "CWE-787",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-21704",
|
|
"Impact": "Low",
|
|
"Public": "20211004",
|
|
"CveID": "CVE-2021-21704"
|
|
},
|
|
{
|
|
"Cvss": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
|
|
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
|
|
"Cwe": "CWE-20",
|
|
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-21705",
|
|
"Impact": "Low",
|
|
"Public": "20211004",
|
|
"CveID": "CVE-2021-21705"
|
|
}
|
|
],
|
|
"AffectedCpeList": {
|
|
"Cpe": [
|
|
"cpe:/o:alt:kworkstation:9",
|
|
"cpe:/o:alt:workstation:9",
|
|
"cpe:/o:alt:server:9",
|
|
"cpe:/o:alt:server-v:9",
|
|
"cpe:/o:alt:education:9",
|
|
"cpe:/o:alt:slinux:9",
|
|
"cpe:/o:alt:starterkit:p9",
|
|
"cpe:/o:alt:kworkstation:9.1",
|
|
"cpe:/o:alt:workstation:9.1",
|
|
"cpe:/o:alt:server:9.1",
|
|
"cpe:/o:alt:server-v:9.1",
|
|
"cpe:/o:alt:education:9.1",
|
|
"cpe:/o:alt:slinux:9.1",
|
|
"cpe:/o:alt:starterkit:9.1",
|
|
"cpe:/o:alt:kworkstation:9.2",
|
|
"cpe:/o:alt:workstation:9.2",
|
|
"cpe:/o:alt:server:9.2",
|
|
"cpe:/o:alt:server-v:9.2",
|
|
"cpe:/o:alt:education:9.2",
|
|
"cpe:/o:alt:slinux:9.2",
|
|
"cpe:/o:alt:starterkit:9.2"
|
|
]
|
|
}
|
|
}
|
|
},
|
|
"Criteria": {
|
|
"Operator": "AND",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:1001",
|
|
"Comment": "ALT Linux must be installed"
|
|
}
|
|
],
|
|
"Criterias": [
|
|
{
|
|
"Operator": "OR",
|
|
"Criterions": [
|
|
{
|
|
"TestRef": "oval:org.altlinux.errata:tst:20212819001",
|
|
"Comment": "php7-opcache is earlier than 0:7.3.30-alt1.3"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
} |