{"cves":[{"id":"CVE-2023-43361","published":"2023-10-02T21:15:00","updated_at":"2025-07-11T07:55:56.798631+00:00","description":"\nBuffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local\nattacker to execute arbitrary code and cause a denial of service during the\nconversion of wav files to ogg files.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/xiph/vorbis-tools","https://github.com/xiph/vorbis-tools/issues/41","https://github.com/xiph/vorbis","https://xiph.org/vorbis/","https://www.cve.org/CVERecord?id=CVE-2023-43361"],"bugs":[""],"patches":{"vorbis-tools":[]},"tags":{},"packages":[{"name":"vorbis-tools","source":"https://ubuntu.com/security/cve?package=vorbis-tools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vorbis-tools","debian":"https://tracker.debian.org/pkg/vorbis-tools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-5344","published":"2023-10-02T20:15:00","updated_at":"2025-08-26T00:18:40.964149+00:00","description":"\nHeap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/vim/vim/commit/3bd7fa12e146c6051490d048a4acbfba974eeb04","https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf","https://ubuntu.com/security/notices/USN-6452-1","https://www.cve.org/CVERecord?id=CVE-2023-5344"],"bugs":[""],"patches":{"vim":[]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2:9.0.1672-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:8.0.1453-1ubuntu1.13+esm6","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2:8.1.2269-1ubuntu5.20","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.13","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2:9.0.1000-4ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:7.4.052-1ubuntu3.1+esm14","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2:7.4.1689-3ubuntu1.5+esm20","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-6452-1"],"notices":[{"id":"USN-6452-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-10-25T16:47:19.738997","description":"It was discovered that Vim could be made to divide by zero. An attacker\ncould possibly use this issue to cause a denial of service. This issue\nonly affected Ubuntu 23.04. (CVE-2023-3896)\n\nIt was discovered that Vim did not properly manage memory. An attacker\ncould possibly use this issue to cause a denial of service or execute\narbitrary code. (CVE-2023-4733, CVE-2023-4750)\n\nIt was discovered that Vim contained an arithmetic overflow. An attacker\ncould possibly use this issue to cause a denial of service. This issue\nonly affected Ubuntu 22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10.\n(CVE-2023-4734)\n\nIt was discovered that Vim could be made to write out of bounds. An\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2023-4735, CVE-2023-5344)\n\nIt was discovered that Vim could be made to write out of bounds. An\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 23.04 and Ubuntu\n23.10. (CVE-2023-4738)\n\nIt was discovered that Vim could be made to write out of bounds. An\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu\n16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and\nUbuntu 23.04. (CVE-2023-4751)\n\nIt was discovered that Vim did not properly manage memory. An attacker\ncould possibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04\nLTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-4752, CVE-2023-5535)\n\nIt was discovered that Vim could be made to write out of bounds. An\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n22.04 LTS, Ubuntu 23.04, and Ubuntu 23.10. (CVE-2023-4781)\n\nIt was discovered that Vim could be made to dereference invalid memory. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2023-5441)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm6","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.20","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.20","pocket":"security"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.13","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.13","pocket":"security"}],"lunar":[{"name":"vim","version":"2:9.0.1000-4ubuntu3.2","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-athena","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-common","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-doc","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-gtk3","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-gui-common","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-motif","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-nox","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-runtime","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"vim-tiny","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"},{"name":"xxd","version":"2:9.0.1000-4ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1000-4ubuntu3.2","pocket":"security"}],"mantic":[{"name":"vim","version":"2:9.0.1672-1ubuntu2.1","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-athena","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-common","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-doc","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-gtk3","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-gui-common","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-motif","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-nox","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-runtime","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"vim-tiny","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"},{"name":"xxd","version":"2:9.0.1672-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.0.1672-1ubuntu2.1","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm14","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"vim","version":"2:7.4.1689-3ubuntu1.5+esm20","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena-py2","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome-py2","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk-py2","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3-py2","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox-py2","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.1689-3ubuntu1.5+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2023-4752","CVE-2023-5535","CVE-2023-4733","CVE-2023-4750","CVE-2023-3896","CVE-2023-4781","CVE-2023-5344","CVE-2023-4751","CVE-2023-5441","CVE-2023-4735","CVE-2023-4738","CVE-2023-4734"]}]},{"id":"CVE-2023-3592","published":"2023-10-02T20:15:00","updated_at":"2025-08-26T00:12:52.722837+00:00","description":"\nIn Mosquitto before 2.0.16, a memory leak occurs when clients send v5\nCONNECT packets with a will message that contains invalid property types.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://mosquitto.org/blog/2023/08/version-2-0-16-released/","https://github.com/eclipse/mosquitto/commit/00b24e0eb0686e9a76feb71fdaee650cb7e612fa (v2.0.16)","https://ubuntu.com/security/notices/USN-6492-1","https://www.cve.org/CVERecord?id=CVE-2023-3592"],"bugs":[""],"patches":{"mosquitto":[]},"tags":{},"packages":[{"name":"mosquitto","source":"https://ubuntu.com/security/cve?package=mosquitto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mosquitto","debian":"https://tracker.debian.org/pkg/mosquitto","statuses":[{"release_codename":"mantic","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.6.9-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.0.11-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2.0.11-1.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6492-1"],"notices":[{"id":"USN-6492-1","title":"Mosquitto vulnerabilities","summary":"Several security issues were fixed in Mosquitto.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-21T15:23:51.936272","description":"Kathrin Kleinhammer discovered that Mosquitto incorrectly handled certain\ninputs. If a user or an automated system were provided with a specially crafted\ninput, a remote attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-34431)\n\nZhanxiang Song discovered that Mosquitto incorrectly handled certain inputs. If\na user or an automated system were provided with a specially crafted input, a\nremote attacker could possibly use this issue to cause an authorisation bypass.\nThis issue only affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2021-34434)\n\nZhanxiang Song, Bin Yuan, DeQing Zou, and Hai Jin discovered that Mosquitto\nincorrectly handled certain inputs. If a user or an automated system were\nprovided with a specially crafted input, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu 20.04\nLTS and Ubuntu 22.04 LTS. (CVE-2021-41039)\n\nZhengjie Du discovered that Mosquitto incorrectly handled certain inputs. If a\nuser or an automated system were provided with a specially crafted input file,\na remote attacker could possibly use this issue to cause a denial of service.\n(CVE-2023-0809)\n\nIt was discovered that Mosquitto incorrectly handled certain inputs. If a user\nor an automated system were provided with a specially crafted input, a remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2023-3592)\n\nMischa Bachmann discovered that Mosquitto incorrectly handled certain inputs.\nIf a user or an automated system were provided with a specially crafted input,\na remote attacker could possibly use this issue to cause a denial of service.\nThis issue was only fixed in Ubuntu 22.04 LTS and Ubuntu 23.04.\n(CVE-2023-28366)\n","is_hidden":false,"release_packages":{"focal":[{"name":"mosquitto","version":"1.6.9-1ubuntu0.1~esm1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquitto1","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquittopp-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquittopp1","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto-clients","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"mosquitto","version":"2.0.11-1ubuntu1.1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquitto1","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquittopp-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquittopp1","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto-clients","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"}],"lunar":[{"name":"mosquitto","version":"2.0.11-1.2ubuntu0.1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquitto1","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquittopp-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquittopp1","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto-clients","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2023-0809","CVE-2021-34434","CVE-2023-28366","CVE-2021-41039","CVE-2023-3592","CVE-2021-34431"]}]},{"id":"CVE-2023-0809","published":"2023-10-02T19:15:00","updated_at":"2025-08-26T00:07:01.923257+00:00","description":"\nIn Mosquitto before 2.0.16, excessive memory is allocated based on\nmalicious initial packets that are not CONNECT packets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://mosquitto.org/blog/2023/08/version-2-0-16-released/","https://ubuntu.com/security/notices/USN-6492-1","https://www.cve.org/CVERecord?id=CVE-2023-0809"],"bugs":[""],"patches":{"mosquitto":[]},"tags":{},"packages":[{"name":"mosquitto","source":"https://ubuntu.com/security/cve?package=mosquitto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mosquitto","debian":"https://tracker.debian.org/pkg/mosquitto","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.6.9-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.0.11-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2.0.11-1.2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6492-1"],"notices":[{"id":"USN-6492-1","title":"Mosquitto vulnerabilities","summary":"Several security issues were fixed in Mosquitto.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-21T15:23:51.936272","description":"Kathrin Kleinhammer discovered that Mosquitto incorrectly handled certain\ninputs. If a user or an automated system were provided with a specially crafted\ninput, a remote attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-34431)\n\nZhanxiang Song discovered that Mosquitto incorrectly handled certain inputs. If\na user or an automated system were provided with a specially crafted input, a\nremote attacker could possibly use this issue to cause an authorisation bypass.\nThis issue only affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2021-34434)\n\nZhanxiang Song, Bin Yuan, DeQing Zou, and Hai Jin discovered that Mosquitto\nincorrectly handled certain inputs. If a user or an automated system were\nprovided with a specially crafted input, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu 20.04\nLTS and Ubuntu 22.04 LTS. (CVE-2021-41039)\n\nZhengjie Du discovered that Mosquitto incorrectly handled certain inputs. If a\nuser or an automated system were provided with a specially crafted input file,\na remote attacker could possibly use this issue to cause a denial of service.\n(CVE-2023-0809)\n\nIt was discovered that Mosquitto incorrectly handled certain inputs. If a user\nor an automated system were provided with a specially crafted input, a remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2023-3592)\n\nMischa Bachmann discovered that Mosquitto incorrectly handled certain inputs.\nIf a user or an automated system were provided with a specially crafted input,\na remote attacker could possibly use this issue to cause a denial of service.\nThis issue was only fixed in Ubuntu 22.04 LTS and Ubuntu 23.04.\n(CVE-2023-28366)\n","is_hidden":false,"release_packages":{"focal":[{"name":"mosquitto","version":"1.6.9-1ubuntu0.1~esm1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquitto1","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquittopp-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquittopp1","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto-clients","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"mosquitto","version":"2.0.11-1ubuntu1.1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquitto1","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquittopp-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquittopp1","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto-clients","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"}],"lunar":[{"name":"mosquitto","version":"2.0.11-1.2ubuntu0.1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquitto1","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquittopp-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquittopp1","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto-clients","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2023-0809","CVE-2021-34434","CVE-2023-28366","CVE-2021-41039","CVE-2023-3592","CVE-2021-34431"]}]},{"id":"CVE-2023-5106","published":"2023-10-02T12:15:00","updated_at":"2025-08-26T00:16:50.079810+00:00","description":"\nAn issue has been discovered in Ultimate-licensed GitLab EE affecting all\nversions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0\nprior to 16.4.1 that could allow an attacker to impersonate users in CI\npipelines through direct transfer group imports.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/gitlab/-/commit/67039cfcae80b8fc0496f79be88714873cd169b3","https://www.cve.org/CVERecord?id=CVE-2023-5106"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-44488","published":"2023-10-02T00:00:00","updated_at":"2025-08-19T22:09:43.518215+00:00","description":"\nVP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related\nto encoding.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2023/09/30/4","https://ubuntu.com/security/notices/USN-6403-1","https://ubuntu.com/security/notices/USN-6403-2","https://ubuntu.com/security/notices/USN-6403-3","https://www.cve.org/CVERecord?id=CVE-2023-44488"],"bugs":[""],"patches":{"chromium-browser":[],"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"libvpx":["upstream: https://github.com/webmproject/libvpx/commit/263682c9a29395055f3b3afe2d97be1828a6223f","upstream: https://github.com/webmproject/libvpx/commit/df9fd9d5b7325060b2b921558a1eb20ca7880937"]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"118.0.1+build1-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"118.0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"libvpx","source":"https://ubuntu.com/security/cve?package=libvpx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libvpx","debian":"https://tracker.debian.org/pkg/libvpx","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.8.2-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.11.0-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.12.0-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.12.0-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.7.0-3ubuntu0.18.04.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.5.0-2ubuntu1.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"noble","status":"released","description":"1.12.0-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.12.0-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.12.0-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.12.0-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.12.0-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6403-1","USN-6403-2","USN-6403-3"],"notices":[{"id":"USN-6403-1","title":"libvpx vulnerabilities","summary":"Several security issues were fixed in libvpx.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-10-02T16:47:37.274463","description":"It was discovered that libvpx did not properly handle certain malformed\nmedia files. If an application using libvpx opened a specially crafted\nfile, a remote attacker could cause a denial of service, or possibly\nexecute arbitrary code.\n","is_hidden":false,"release_packages":{"focal":[{"name":"libvpx","version":"1.8.2-1ubuntu0.2","description":"VP8 and VP9 video codec","is_source":true},{"name":"libvpx-dev","version":"1.8.2-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.8.2-1ubuntu0.2","pocket":"security"},{"name":"libvpx-doc","version":"1.8.2-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.8.2-1ubuntu0.2","pocket":"security"},{"name":"libvpx6","version":"1.8.2-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.8.2-1ubuntu0.2","pocket":"security"},{"name":"vpx-tools","version":"1.8.2-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.8.2-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"libvpx","version":"1.11.0-2ubuntu2.2","description":"VP8 and VP9 video codec","is_source":true},{"name":"libvpx-dev","version":"1.11.0-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.11.0-2ubuntu2.2","pocket":"security"},{"name":"libvpx-doc","version":"1.11.0-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.11.0-2ubuntu2.2","pocket":"security"},{"name":"libvpx7","version":"1.11.0-2ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.11.0-2ubuntu2.2","pocket":"security"},{"name":"vpx-tools","version":"1.11.0-2ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.11.0-2ubuntu2.2","pocket":"security"}],"lunar":[{"name":"libvpx","version":"1.12.0-1ubuntu1.2","description":"VP8 and VP9 video codec","is_source":true},{"name":"libvpx-dev","version":"1.12.0-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.12.0-1ubuntu1.2","pocket":"security"},{"name":"libvpx-doc","version":"1.12.0-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.12.0-1ubuntu1.2","pocket":"security"},{"name":"libvpx7","version":"1.12.0-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.12.0-1ubuntu1.2","pocket":"security"},{"name":"vpx-tools","version":"1.12.0-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":"https://launchpad.net/ubuntu/+source/libvpx/1.12.0-1ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2023-44488","CVE-2023-5217"]},{"id":"USN-6403-2","title":"libvpx vulnerabilities","summary":"Several security issues were fixed in libvpx.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-10-23T15:46:57.858495","description":"USN-6403-1 fixed several vulnerabilities in libvpx. This update provides\nthe corresponding update for Ubuntu 18.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that libvpx did not properly handle certain malformed\n media files. If an application using libvpx opened a specially crafted\n file, a remote attacker could cause a denial of service, or possibly\n execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libvpx","version":"1.7.0-3ubuntu0.18.04.1+esm1","description":"VP8 and VP9 video codec","is_source":true},{"name":"libvpx-dev","version":"1.7.0-3ubuntu0.18.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"},{"name":"libvpx-doc","version":"1.7.0-3ubuntu0.18.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"},{"name":"libvpx5","version":"1.7.0-3ubuntu0.18.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"},{"name":"vpx-tools","version":"1.7.0-3ubuntu0.18.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2023-5217","CVE-2023-44488"]},{"id":"USN-6403-3","title":"libvpx vulnerabilities","summary":"Several security issues were fixed in libvpx.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-01T09:29:41.502836","description":"USN-6403-1 fixed several vulnerabilities in libvpx. This update provides\nthe corresponding update for Ubuntu 16.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that libvpx did not properly handle certain malformed\n media files. If an application using libvpx opened a specially crafted\n file, a remote attacker could cause a denial of service, or possibly\n execute arbitrary code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libvpx","version":"1.5.0-2ubuntu1.1+esm2","description":"VP8 and VP9 video codec","is_source":true},{"name":"libvpx-dev","version":"1.5.0-2ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"},{"name":"libvpx-doc","version":"1.5.0-2ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"},{"name":"libvpx3","version":"1.5.0-2ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"},{"name":"vpx-tools","version":"1.5.0-2ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvpx","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2023-44488","CVE-2023-5217"]}]},{"id":"CVE-2023-5323","published":"2023-10-01T01:15:00","updated_at":"2025-08-26T14:05:59.349669+00:00","description":"\nCross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr\nprior to 18.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/dolibarr/dolibarr/commit/695ca086847b3b6a185afa93e897972c93c43d15","https://huntr.dev/bounties/7a048bb7-bfdd-4299-931e-9bc283e92bc8","https://www.cve.org/CVERecord?id=CVE-2023-5323"],"bugs":[""],"patches":{"dolibarr":[]},"tags":{},"packages":[{"name":"dolibarr","source":"https://ubuntu.com/security/cve?package=dolibarr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dolibarr","debian":"https://tracker.debian.org/pkg/dolibarr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-43907","published":"2023-10-01T01:15:00","updated_at":"2025-08-26T18:01:05.279980+00:00","description":"\nOptiPNG v0.7.7 was discovered to contain a global buffer overflow via the\n'buffer' variable at gifread.c.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nDenial of service only in command-line tool"},{"author":"mdeslaur","note":"Can't reproduce with PoC on focal, jammy, and lunar. This is\nan out-of-bounds read in a command-line tool, unlikely to have\nany security impact."}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Frank-Z7/z-vulnerabilitys/blob/main/optipng-global-buffer-overflow1/optipng-global-buffer-overflow1.md","http://optipng.sourceforge.net/","https://sourceforge.net/projects/optipng/files/OptiPNG/optipng-0.7.7/optipng-0.7.7.tar.gz/download?use_mirror=udomain&download=","https://www.cve.org/CVERecord?id=CVE-2023-43907"],"bugs":["https://sourceforge.net/p/optipng/bugs/87/"],"patches":{"optipng":[]},"tags":{},"packages":[{"name":"optipng","source":"https://ubuntu.com/security/cve?package=optipng","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=optipng","debian":"https://tracker.debian.org/pkg/optipng","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.7.8+ds-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was deferred [2023-10-10]","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was deferred [2023-10-10]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.7.8+ds-1build2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.7.8+ds-1build2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.7.8+ds-1build2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.7.8+ds-1build2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.7.8+ds-1build2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-5207","published":"2023-09-30T09:15:00","updated_at":"2025-08-26T00:16:59.302178+00:00","description":"\nA vulnerability was discovered in GitLab CE and EE affecting all versions\nstarting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to\n16.4.1. An authenticated attacker could perform arbitrary pipeline\nexecution under the context of another user.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://hackerone.com/reports/2174141","https://gitlab.com/gitlab-org/gitlab/-/issues/425604","https://gitlab.com/gitlab-org/gitlab/-/issues/425857","https://www.cve.org/CVERecord?id=CVE-2023-5207"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-44270","published":"2023-09-29T22:15:00","updated_at":"2025-07-11T07:56:03.002709+00:00","description":"\nAn issue was discovered in PostCSS before 8.4.31. The vulnerability affects\nlinters using PostCSS to parse external untrusted CSS. An attacker can\nprepare CSS in such a way that it will contains parts parsed by PostCSS as\na CSS comment. After processing by PostCSS, it will be included in the\nPostCSS output in CSS nodes (rules, properties) despite being included in a\ncomment.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5 (8.4.31)","https://github.com/postcss/postcss/blob/main/lib/tokenize.js#L25","https://github.com/postcss/postcss/commit/58cc860b4c1707510c9cd1bc1fa30b423a9ad6c5","https://github.com/postcss/postcss/releases/tag/8.4.31","https://www.cve.org/CVERecord?id=CVE-2023-44270"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1053282"],"patches":{"node-postcss":[]},"tags":{},"packages":[{"name":"node-postcss","source":"https://ubuntu.com/security/cve?package=node-postcss","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-postcss","debian":"https://tracker.debian.org/pkg/node-postcss","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-43655","published":"2023-09-29T20:15:00","updated_at":"2025-07-02T02:44:06.320270+00:00","description":"\nComposer is a dependency manager for PHP. Users publishing a composer.phar\nto a public web-accessible server where the composer.phar can be executed\nas a php file may be subject to a remote code execution vulnerability if\nPHP also has `register_argc_argv` enabled in php.ini. Versions 2.6.4,\n2.2.22 and 1.10.27 patch this vulnerability. Users are advised to upgrade.\nUsers unable to upgrade should make sure `register_argc_argv` is disabled\nin php.ini, and avoid publishing composer.phar to the web as this is not\nbest practice.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/composer/composer/security/advisories/GHSA-jm6m-4632-36hf","https://github.com/composer/composer/commit/4fce14795aba98e40b6c4f5047305aba17a6120d (1.10.27)","https://github.com/composer/composer/commit/95e091c921037b7b6564942845e7b738f6b95c9c (2.2.22)","https://github.com/composer/composer/commit/955a48e6319c8962e5cd421b07c00ab3c728968c (2.6.4)","https://github.com/composer/composer/commit/955a48e6319c8962e5cd421b07c00ab3c728968c","https://github.com/composer/composer/commit/95e091c921037b7b6564942845e7b738f6b95c9c","https://github.com/composer/composer/commit/4fce14795aba98e40b6c4f5047305aba17a6120d","https://www.cve.org/CVERecord?id=CVE-2023-43655","https://ubuntu.com/security/notices/USN-7603-1"],"bugs":[""],"patches":{"composer":[]},"tags":{},"packages":[{"name":"composer","source":"https://ubuntu.com/security/cve?package=composer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=composer","debian":"https://tracker.debian.org/pkg/composer","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.3-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.10.1-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.7.1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.7.7-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.8.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.27, 2.2.22, 2.6.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.2.6-2ubuntu4+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1.0.0~beta2-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"not-affected","description":"2.8.8-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.8.8-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-7603-1"],"notices":[{"id":"USN-7603-1","title":"Composer vulnerabilities","summary":"Several security issues were fixed in Composer.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-06-30T04:29:26.999718","description":"Thomas Chauchefoin discovered that Composer did not correctly handle\ncertain arguments. An attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS,\nUbuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.\n(CVE-2022-24828, CVE-2023-43655)\n\nEd Cradock discovered that Composer did not correctly handle the exclusion\nof certain files. An attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2024-24821)\n\nMartin Haunschmid discovered that Composer did not correctly handle git\nbranch names. An attacker could possibly use this issue to execute\narbitrary code. (CVE-2024-35241)\n\nMaciej Piechota discovered that Composer did not correctly handle VCS\nbranch names. An attacker could possibly use this issue to execute\narbitrary code. (CVE-2024-35242)","is_hidden":false,"release_packages":{"bionic":[{"name":"composer","version":"1.6.3-1ubuntu0.1~esm2","description":"Dependency Manager for PHP","is_source":true},{"name":"composer","version":"1.6.3-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/composer","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"composer","version":"1.10.1-1ubuntu0.1~esm2","description":"Dependency Manager for PHP","is_source":true},{"name":"composer","version":"1.10.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/composer","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"composer","version":"2.2.6-2ubuntu4+esm1","description":"Dependency Manager for PHP","is_source":true},{"name":"composer","version":"2.2.6-2ubuntu4+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/composer","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"composer","version":"2.7.1-2ubuntu0.1~esm1","description":"Dependency Manager for PHP","is_source":true},{"name":"composer","version":"2.7.1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/composer","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"composer","version":"1.0.0~beta2-1ubuntu0.1~esm2","description":"Dependency Manager for PHP","is_source":true},{"name":"composer","version":"1.0.0~beta2-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/composer","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2024-35241","CVE-2024-35242","CVE-2024-24821","CVE-2022-24828","CVE-2023-43655"]}]},{"id":"CVE-2023-3413","published":"2023-09-29T09:15:00","updated_at":"2025-08-26T00:12:27.598164+00:00","description":"\nAn issue has been discovered in GitLab affecting all versions starting from\n16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all\nversions starting from 16.4 before 16.4.1. It was possible to read the\nsource code of a project through a fork created before changing visibility\nto only project members.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-3413"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-5198","published":"2023-09-29T08:15:00","updated_at":"2025-08-26T00:16:59.302178+00:00","description":"\nAn issue has been discovered in GitLab affecting all versions prior to\n16.2.7, all versions starting from 16.3 before 16.3.5, and all versions\nstarting from 16.4 before 16.4.1. It was possible for a removed project\nmember to write to protected branches using deploy keys.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-5198"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-3922","published":"2023-09-29T08:15:00","updated_at":"2025-08-26T00:13:56.819847+00:00","description":"\nAn issue has been discovered in GitLab affecting all versions starting from\n8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all\nversions starting from 16.4 before 16.4.1. It was possible to hijack some\nlinks and buttons on the GitLab UI to a malicious page.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-3922"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-4532","published":"2023-09-29T07:15:00","updated_at":"2025-08-26T00:15:32.492109+00:00","description":"\nAn issue has been discovered in GitLab affecting all versions starting from\n16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all\nversions starting from 16.4 before 16.4.1. Users were capable of linking\nCI/CD jobs of private projects which they are not a member of.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-4532"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-3979","published":"2023-09-29T07:15:00","updated_at":"2025-08-26T00:14:06.146267+00:00","description":"\nAn issue has been discovered in GitLab affecting all versions starting from\n10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all\nversions starting from 16.4 before 16.4.1. It was possible that upstream\nmembers to collaborate with you on your branch get permission to write to\nthe merge request’s source branch.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-3979"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-3920","published":"2023-09-29T07:15:00","updated_at":"2025-08-26T00:13:56.819847+00:00","description":"\nAn issue has been discovered in GitLab affecting all versions starting from\n11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all\nversions starting from 16.4 before 16.4.1. It was possible that a\nmaintainer to create a fork relationship between existing projects contrary\nto the documentation.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-3920"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-3917","published":"2023-09-29T07:15:00","updated_at":"2025-07-11T07:55:43.404102+00:00","description":"\nDenial of Service in pipelines affecting all versions of Gitlab EE and CE\nprior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows\nattacker to cause pipelines to fail.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-3917"],"bugs":[""],"patches":{"gitlab":[],"gitlab-agent":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.4.4+ds2-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gitlab-agent","source":"https://ubuntu.com/security/cve?package=gitlab-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab-agent","debian":"https://tracker.debian.org/pkg/gitlab-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-2233","published":"2023-09-29T07:15:00","updated_at":"2025-08-26T00:08:23.586415+00:00","description":"\nAn improper authorization issue has been discovered in GitLab CE/EE\naffecting all versions starting from 11.8 before 16.2.8, all versions\nstarting from 16.3 before 16.3.5 and all versions starting from 16.4 before\n16.4.1. It allows a project reporter to leak the owner's Sentry instance\nprojects.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-2233"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.4.4+ds2-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [not maintainable]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-0989","published":"2023-09-29T07:15:00","updated_at":"2025-08-26T00:07:06.843266+00:00","description":"\nAn information disclosure issue in GitLab CE/EE affecting all versions\nstarting from 13.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior\nto 16.4.1 allows an attacker to extract non-protected CI/CD variables by\ntricking a user to visit a fork with a malicious CI/CD configuration.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-0989"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.4.4+ds2-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [not maintainable]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":33320,"limit":20,"total_results":79316}