2024-06-28 13:17:52 +00:00

159 lines
6.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20181520",
"Version": "oval:org.altlinux.errata:def:20181520",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2018-1520: package `ImageMagick` update to version 6.9.9.40-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2018-1520",
"RefURL": "https://errata.altlinux.org/ALT-PU-2018-1520",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-03441",
"RefURL": "https://bdu.fstec.ru/vul/2021-03441",
"Source": "BDU"
},
{
"RefID": "CVE-2018-6405",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2018-6405",
"Source": "CVE"
},
{
"RefID": "CVE-2019-10131",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-10131",
"Source": "CVE"
}
],
"Description": "This update upgrades ImageMagick to version 6.9.9.40-alt1. \nSecurity Fix(es):\n\n * BDU:2021-03441: Уязвимость функции formatIPTCfromBuffer компонента coders/meta.c консольного графического редактора ImageMagick, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании\n\n * CVE-2018-6405: In the ReadDCMImage function in coders/dcm.c in ImageMagick before 7.0.7-23, each redmap, greenmap, and bluemap variable can be overwritten by a new pointer. The previous pointer is lost, which leads to a memory leak. This allows remote attackers to cause a denial of service.\n\n * CVE-2019-10131: An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer function in coders/meta.c. A local attacker may use this flaw to read beyond the end of the buffer or to crash the program.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2018-03-31"
},
"Updated": {
"Date": "2018-03-31"
},
"BDUs": [
{
"ID": "BDU:2021-03441",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2021-03441",
"Impact": "High",
"Public": "20180315"
}
],
"CVEs": [
{
"ID": "CVE-2018-6405",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"CWE": "CWE-772",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2018-6405",
"Impact": "Low",
"Public": "20180130"
},
{
"ID": "CVE-2019-10131",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"CWE": "CWE-193",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-10131",
"Impact": "High",
"Public": "20190430"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20181520001",
"Comment": "ImageMagick is earlier than 0:6.9.9.40-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181520002",
"Comment": "ImageMagick-doc is earlier than 0:6.9.9.40-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181520003",
"Comment": "ImageMagick-tools is earlier than 0:6.9.9.40-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181520004",
"Comment": "libImageMagick is earlier than 0:6.9.9.40-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181520005",
"Comment": "libImageMagick-devel is earlier than 0:6.9.9.40-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20181520006",
"Comment": "perl-Magick is earlier than 0:6.9.9.40-alt1"
}
]
}
]
}
}
]
}