forked from aquasecurity/trivy-db
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(slemicro): enable SUSE Linux Enterprise Micro
aquasecurity/trivy#7221 Signed-off-by: Marcus Meissner <[email protected]>
- Loading branch information
Showing
3 changed files
with
229 additions
and
6 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
156 changes: 156 additions & 0 deletions
156
...tdata/happy/SUSE Linux Enterprise Micro/vuln-list/cvrf/suse/suse/SUSE-SU-2024-2546-1.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,156 @@ | ||
{ | ||
"Title": "Security update for gnutls", | ||
"Tracking": { | ||
"ID": "SUSE-SU-2024:2546-1", | ||
"Status": "Final", | ||
"Version": "1", | ||
"InitialReleaseDate": "2024-07-17T12:44:32Z", | ||
"CurrentReleaseDate": "2024-07-17T12:44:32Z", | ||
"RevisionHistory": [ | ||
{ | ||
"Number": "1", | ||
"Date": "2024-07-17T12:44:32Z", | ||
"Description": "current" | ||
} | ||
] | ||
}, | ||
"Notes": [ | ||
{ | ||
"Text": "Security update for gnutls", | ||
"Title": "Topic", | ||
"Type": "Summary" | ||
}, | ||
{ | ||
"Text": "This update for gnutls fixes the following issues:\n\n- CVE-2024-28835: Fixed a certtool crash when verifying a certificate\n chain (bsc#1221747).\n- CVE-2024-28834: Fixed a side-channel attack in the deterministic\n ECDSA (bsc#1221746).\n\nOther fixes:\n\n- Fixed a memory leak when using the entropy collector (bsc#1221242).\n", | ||
"Title": "Details", | ||
"Type": "General" | ||
}, | ||
{ | ||
"Text": "The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", | ||
"Title": "Terms of Use", | ||
"Type": "Legal Disclaimer" | ||
}, | ||
{ | ||
"Text": "SUSE-2024-2546,SUSE-SLE-Micro-5.3-2024-2546", | ||
"Title": "Patchnames", | ||
"Type": "Details" | ||
} | ||
], | ||
"ProductTree": { | ||
"Relationships": [ | ||
{ | ||
"ProductReference": "gnutls-3.7.3-150400.8.1", | ||
"RelatesToProductReference": "SUSE Linux Enterprise Micro 5.3", | ||
"RelationType": "Default Component Of" | ||
}, | ||
{ | ||
"ProductReference": "libgnutls30-3.7.3-150400.8.1", | ||
"RelatesToProductReference": "SUSE Linux Enterprise Micro 5.3", | ||
"RelationType": "Default Component Of" | ||
}, | ||
{ | ||
"ProductReference": "libgnutls30-hmac-3.7.3-150400.8.1", | ||
"RelatesToProductReference": "SUSE Linux Enterprise Micro 5.3", | ||
"RelationType": "Default Component Of" | ||
} | ||
] | ||
}, | ||
"References": [ | ||
{ | ||
"URL": "https://www.suse.com/support/update/announcement/2024/suse-su-20242546-1/", | ||
"Description": "Link for SUSE-SU-2024:2546-1" | ||
}, | ||
{ | ||
"URL": "https://lists.suse.com/pipermail/sle-security-updates/2024-July/018994.html", | ||
"Description": "E-Mail link for SUSE-SU-2024:2546-1" | ||
}, | ||
{ | ||
"URL": "https://www.suse.com/support/security/rating/", | ||
"Description": "SUSE Security Ratings" | ||
}, | ||
{ | ||
"URL": "https://bugzilla.suse.com/1221242", | ||
"Description": "SUSE Bug 1221242" | ||
}, | ||
{ | ||
"URL": "https://bugzilla.suse.com/1221746", | ||
"Description": "SUSE Bug 1221746" | ||
}, | ||
{ | ||
"URL": "https://bugzilla.suse.com/1221747", | ||
"Description": "SUSE Bug 1221747" | ||
}, | ||
{ | ||
"URL": "https://www.suse.com/security/cve/CVE-2024-28834/", | ||
"Description": "SUSE CVE CVE-2024-28834 page" | ||
}, | ||
{ | ||
"URL": "https://www.suse.com/security/cve/CVE-2024-28835/", | ||
"Description": "SUSE CVE CVE-2024-28835 page" | ||
} | ||
], | ||
"Vulnerabilities": [ | ||
{ | ||
"CVE": "CVE-2024-28834", | ||
"Description": "A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel.", | ||
"Threats": [ | ||
{ | ||
"Type": "Impact", | ||
"Severity": "moderate" | ||
} | ||
], | ||
"References": [ | ||
{ | ||
"URL": "https://www.suse.com/security/cve/CVE-2024-28834.html", | ||
"Description": "CVE-2024-28834" | ||
}, | ||
{ | ||
"URL": "https://bugzilla.suse.com/1221746", | ||
"Description": "SUSE Bug 1221746" | ||
} | ||
], | ||
"ProductStatuses": [ | ||
{ | ||
"Type": "Fixed", | ||
"ProductID": [ | ||
"SUSE Linux Enterprise Micro 5.3:gnutls-3.7.3-150400.8.1", | ||
"SUSE Linux Enterprise Micro 5.3:libgnutls30-3.7.3-150400.8.1", | ||
"SUSE Linux Enterprise Micro 5.3:libgnutls30-hmac-3.7.3-150400.8.1" | ||
] | ||
} | ||
], | ||
"CVSSScoreSets": {} | ||
}, | ||
{ | ||
"CVE": "CVE-2024-28835", | ||
"Description": "A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the \"certtool --verify-chain\" command.", | ||
"Threats": [ | ||
{ | ||
"Type": "Impact", | ||
"Severity": "moderate" | ||
} | ||
], | ||
"References": [ | ||
{ | ||
"URL": "https://www.suse.com/security/cve/CVE-2024-28835.html", | ||
"Description": "CVE-2024-28835" | ||
}, | ||
{ | ||
"URL": "https://bugzilla.suse.com/1221747", | ||
"Description": "SUSE Bug 1221747" | ||
} | ||
], | ||
"ProductStatuses": [ | ||
{ | ||
"Type": "Fixed", | ||
"ProductID": [ | ||
"SUSE Linux Enterprise Micro 5.3:gnutls-3.7.3-150400.8.1", | ||
"SUSE Linux Enterprise Micro 5.3:libgnutls30-3.7.3-150400.8.1", | ||
"SUSE Linux Enterprise Micro 5.3:libgnutls30-hmac-3.7.3-150400.8.1" | ||
] | ||
} | ||
], | ||
"CVSSScoreSets": {} | ||
} | ||
] | ||
} |