2024-02-14 09:47:22 +00:00

173 lines
6.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20192751",
"Version": "oval:org.altlinux.errata:def:20192751",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2019-2751: package `poco` update to version 1.9.4-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2019-2751",
"RefURL": "https://errata.altlinux.org/ALT-PU-2019-2751",
"Source": "ALTPU"
},
{
"RefID": "BDU:2019-03643",
"RefURL": "https://bdu.fstec.ru/vul/2019-03643",
"Source": "BDU"
},
{
"RefID": "CVE-2019-15903",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-15903",
"Source": "CVE"
}
],
"Description": "This update upgrades poco to version 1.9.4-alt1. \nSecurity Fix(es):\n\n * BDU:2019-03643: Уязвимость библиотеки для анализа XML-файлов libexpat, связанная с неверным ограничением xml-ссылок на внешние объекты, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2019-15903: In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2019-09-20"
},
"Updated": {
"Date": "2019-09-20"
},
"bdu": [
{
"Cvss": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"Cvss3": "AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"Cwe": "CWE-611",
"Href": "https://bdu.fstec.ru/vul/2019-03643",
"Impact": "High",
"Public": "20190828",
"CveID": "BDU:2019-03643"
}
],
"Cves": [
{
"Cvss": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"Cvss3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"Cwe": "CWE-125",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-15903",
"Impact": "High",
"Public": "20190904",
"CveID": "CVE-2019-15903"
}
],
"AffectedCpeList": {
"Cpe": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20192751001",
"Comment": "libpoco is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751002",
"Comment": "libpoco-crypto is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751003",
"Comment": "libpoco-data is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751004",
"Comment": "libpoco-devel is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751005",
"Comment": "libpoco-mongodb is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751006",
"Comment": "libpoco-mysql is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751007",
"Comment": "libpoco-net is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751008",
"Comment": "libpoco-odbc is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751009",
"Comment": "libpoco-redis is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751010",
"Comment": "libpoco-sqlite is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751011",
"Comment": "libpoco-ssl is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751012",
"Comment": "libpoco-util is earlier than 0:1.9.4-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20192751013",
"Comment": "libpoco-zip is earlier than 0:1.9.4-alt1"
}
]
}
]
}
}
]
}