2024-06-28 13:17:52 +00:00

145 lines
5.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20193212",
"Version": "oval:org.altlinux.errata:def:20193212",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-3212: package `nss` update to version 3.47.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-3212",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-3212",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-01824",
"RefURL": "https://bdu.fstec.ru/vul/2020-01824",
"Source": "BDU"
},
{
"RefID": "CVE-2019-11745",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-11745",
"Source": "CVE"
}
],
"Description": "This update upgrades nss to version 3.47.1-alt1. \nSecurity Fix(es):\n\n * BDU:2020-01824: Уязвимость браузера Firefox, связанная с записью за границами буфера в памяти, позволяющая нарушителю получить несанкционированный доступ к информации и нарушить ее целостность и доступность\n\n * CVE-2019-11745: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird \u003c 68.3, Firefox ESR \u003c 68.3, and Firefox \u003c 71.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-12-02"
},
"Updated": {
"Date": "2019-12-02"
},
"BDUs": [
{
"ID": "BDU:2020-01824",
"CVSS": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2020-01824",
"Impact": "High",
"Public": "20190927"
}
],
"CVEs": [
{
"ID": "CVE-2019-11745",
"CVSS": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"CWE": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-11745",
"Impact": "High",
"Public": "20200108"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20193212001",
"Comment": "libnss is earlier than 0:3.47.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193212002",
"Comment": "libnss-devel is earlier than 0:3.47.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193212003",
"Comment": "libnss-devel-static is earlier than 0:3.47.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193212004",
"Comment": "libnss-nssckbi-checkinstall is earlier than 0:3.47.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193212005",
"Comment": "libnss-sysinit is earlier than 0:3.47.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20193212006",
"Comment": "nss-utils is earlier than 0:3.47.1-alt1"
}
]
}
]
}
}
]
}