{"cves":[{"id":"CVE-2020-22628","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:44:08.106512+00:00","description":"\nBuffer Overflow vulnerability in LibRaw::stretch() function in\nlibraw\\src\\postprocessing\\aspect_ratio.cpp.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"In focal, code is in dcraw/dcraw.c and\ninternal/dcraw_common.cpp."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6377-1","https://www.cve.org/CVERecord?id=CVE-2020-22628","https://ubuntu.com/security/notices/USN-7266-1"],"bugs":["https://github.com/LibRaw/LibRaw/issues/269"],"patches":{"libraw":[],"ufraw":[],"darktable":[],"exactimage":[],"dcraw":[],"rawtherapee":[],"xbmc":[],"kodi":[],"digikam":[]},"tags":{},"packages":[{"name":"ufraw","source":"https://ubuntu.com/security/cve?package=ufraw","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ufraw","debian":"https://tracker.debian.org/pkg/ufraw","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"darktable","source":"https://ubuntu.com/security/cve?package=darktable","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=darktable","debian":"https://tracker.debian.org/pkg/darktable","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"exactimage","source":"https://ubuntu.com/security/cve?package=exactimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exactimage","debian":"https://tracker.debian.org/pkg/exactimage","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dcraw","source":"https://ubuntu.com/security/cve?package=dcraw","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dcraw","debian":"https://tracker.debian.org/pkg/dcraw","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"rawtherapee","source":"https://ubuntu.com/security/cve?package=rawtherapee","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rawtherapee","debian":"https://tracker.debian.org/pkg/rawtherapee","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kodi","source":"https://ubuntu.com/security/cve?package=kodi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kodi","debian":"https://tracker.debian.org/pkg/kodi","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"digikam","source":"https://ubuntu.com/security/cve?package=digikam","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=digikam","debian":"https://tracker.debian.org/pkg/digikam","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4:6.4.0+dfsg-3ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.0-rc","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libraw","source":"https://ubuntu.com/security/cve?package=libraw","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libraw","debian":"https://tracker.debian.org/pkg/libraw","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.20.2-2ubuntu2.22.04.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.20.0-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.19.5-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xbmc","source":"https://ubuntu.com/security/cve?package=xbmc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xbmc","debian":"https://tracker.debian.org/pkg/xbmc","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6377-1","USN-7266-1"],"notices":[{"id":"USN-6377-1","title":"LibRaw vulnerability","summary":"LibRaw could be made to crash if it opened a specially crafted file.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2023-09-18T13:15:50.817306","description":"It was discovered that LibRaw incorrectly handled certain photo files. If a\nuser o automated system were tricked into processing a specially crafted\nphoto file, a remote attacker could possibly cause applications linked\nagainst LibRaw to crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"focal":[{"name":"libraw","version":"0.19.5-1ubuntu1.3","description":"raw image decoder library","is_source":true},{"name":"libraw-bin","version":"0.19.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.3","pocket":"security"},{"name":"libraw-dev","version":"0.19.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.3","pocket":"security"},{"name":"libraw-doc","version":"0.19.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.3","pocket":"security"},{"name":"libraw19","version":"0.19.5-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-22628"]},{"id":"USN-7266-1","title":"digiKam vulnerabilities","summary":"Several security issues were fixed in digiKam.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2025-02-13T03:28:13.403305","description":"Zinuo Han and Ao Wang discovered that the Android DNG SDK, vendored in\ndigiKam, did not correctly parse certain files. An attacker could possibly\nuse this issue to execute arbitrary code. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2017-0691)\n\nIt was discovered that Platinum Upnp SDK, vendored in digiKam, was\nvulnerable to a path traversal attack. An attacker could possibly use this\nissue to leak sensitive information. This issue only affected \nUbuntu 20.04 LTS. (CVE-2020-19858)\n\nIt was discovered that LibRaw, vendored in digiKam, did not correctly\nhandle certain memory operations. If a user or automated system were\ntricked into opening a specially crafted file, an attacker could possibly\nuse this issue to leak sensitive information. This issue only affected\nUbuntu 20.04 LTS. (CVE-2020-22628)\n\nIt was discovered that LibRaw, vendored in digiKam, did not correctly\nhandle certain memory operations. If a user or automated system were\ntricked into opening a specially crafted file, an attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary code. This\nissue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-35530,\nCVE-2020-35531, CVE-2020-35532, CVE-2020-35533)\n\nIt was discovered that LibRaw, vendored in digiKam, did not correctly\nhandle certain memory operations. If a user or automated system were\ntricked into opening a specially crafted file, an attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary code.\nThis issue only affected Ubuntu 20.04 LTS. (CVE-2021-32142)\n\nIt was discovered that LibRaw, vendored in digiKam, did not correctly\nhandle certain memory operations. If a user or automated system were\ntricked into opening a specially crafted file, an attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary code.\nThis issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and\nUbuntu 22.04 LTS. (CVE-2023-1729)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"digikam","version":"4:5.6.0-0ubuntu10+esm1","description":"digital photo management application for KDE","is_source":true},{"name":"digikam","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-data","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-doc","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-private-libs","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"kipi-plugins","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"kipi-plugins-common","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"showfoto","version":"4:5.6.0-0ubuntu10+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"digikam","version":"4:6.4.0+dfsg-3ubuntu0.1~esm1","description":"digital photo management application for KDE","is_source":true},{"name":"digikam","version":"4:6.4.0+dfsg-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-data","version":"4:6.4.0+dfsg-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-private-libs","version":"4:6.4.0+dfsg-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"showfoto","version":"4:6.4.0+dfsg-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"digikam","version":"4:7.5.0-3ubuntu0.1~esm1","description":"digital photo management application for KDE","is_source":true},{"name":"digikam","version":"4:7.5.0-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-data","version":"4:7.5.0-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-private-libs","version":"4:7.5.0-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"showfoto","version":"4:7.5.0-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"digikam","version":"4:4.12.0-0ubuntu7+esm1","description":"digital photo management application for KDE","is_source":true},{"name":"digikam","version":"4:4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-data","version":"4:4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"digikam-doc","version":"4:4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"kipi-plugins","version":"4:4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"kipi-plugins-common","version":"4:4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"libkvkontakte1","version":"1.0~digikam4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"libmediawiki1","version":"1.0~digikam4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"},{"name":"showfoto","version":"4:4.12.0-0ubuntu7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/digikam","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-35531","CVE-2020-35530","CVE-2017-0691","CVE-2021-32142","CVE-2020-22628","CVE-2020-19858","CVE-2020-35533","CVE-2020-35532","CVE-2023-1729"]}]},{"id":"CVE-2020-22570","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:43.128974+00:00","description":"\nMemcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of\nservice (daemon crash) via a crafted meta command.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.6.0"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2020-22570"],"bugs":["https://github.com/memcached/memcached/issues/636"],"patches":{"memcached":[]},"tags":{},"packages":[{"name":"memcached","source":"https://ubuntu.com/security/cve?package=memcached","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=memcached","debian":"https://tracker.debian.org/pkg/memcached","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.6.14-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-22524","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:43.128974+00:00","description":"\nBuffer Overflow vulnerability in FreeImage_Load function in FreeImage\nLibrary 3.19.0(r1828) allows attackers to cuase a denial of service via\ncrafted PFM file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/freeimage/bugs/319/","https://ubuntu.com/security/notices/USN-6586-1","https://www.cve.org/CVERecord?id=CVE-2020-22524"],"bugs":[""],"patches":{"freeimage":[]},"tags":{},"packages":[{"name":"freeimage","source":"https://ubuntu.com/security/cve?package=freeimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=freeimage","debian":"https://tracker.debian.org/pkg/freeimage","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"3.18.0+ds2-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.18.0+ds2-6ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.18.0+ds2-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.18.0+ds2-9.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.15.4-3ubuntu0.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"3.17.0+ds1-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"3.18.0+ds2-10build4","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.18.0+ds2-10build4","component":null,"pocket":"security"}]}],"notices_ids":["USN-6586-1"],"notices":[{"id":"USN-6586-1","title":"FreeImage vulnerabilities","summary":"Several security issues were fixed in FreeImage.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-01-16T12:44:38.617650","description":"It was discovered that FreeImage incorrectly handled certain memory\noperations. If a user were tricked into opening a crafted TIFF file, a\nremote attacker could use this issue to cause a heap buffer overflow,\nresulting in a denial of service attack. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12211)\n\nIt was discovered that FreeImage incorrectly processed images under\ncertain circumstances. If a user were tricked into opening a crafted TIFF\nfile, a remote attacker could possibly use this issue to cause a stack\nexhaustion condition, resulting in a denial of service attack. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 20.04 LTS. (CVE-2019-12213)\n\nIt was discovered that FreeImage incorrectly processed certain images.\nIf a user or automated system were tricked into opening a specially\ncrafted image file, a remote attacker could possibly use this issue to\ncause a denial of service or execute arbitrary code. (CVE-2020-21427,\nCVE-2020-21428)\n\nIt was discovered that FreeImage incorrectly processed certain images.\nIf a user or automated system were tricked into opening a specially\ncrafted PFM file, an attacker could possibly use this issue to cause a\ndenial of service. (CVE-2020-22524)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"freeimage","version":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimage3","version":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimageplus-dev","version":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimageplus-doc","version":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimageplus3","version":"3.17.0+ds1-5+deb9u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"freeimage","version":"3.18.0+ds2-1ubuntu3.1","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.18.0+ds2-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-1ubuntu3.1","pocket":"security"},{"name":"libfreeimage3","version":"3.18.0+ds2-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-1ubuntu3.1","pocket":"security"},{"name":"libfreeimageplus-dev","version":"3.18.0+ds2-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-1ubuntu3.1","pocket":"security"},{"name":"libfreeimageplus-doc","version":"3.18.0+ds2-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-1ubuntu3.1","pocket":"security"},{"name":"libfreeimageplus3","version":"3.18.0+ds2-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-1ubuntu3.1","pocket":"security"}],"jammy":[{"name":"freeimage","version":"3.18.0+ds2-6ubuntu5.1","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.18.0+ds2-6ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-6ubuntu5.1","pocket":"security"},{"name":"libfreeimage3","version":"3.18.0+ds2-6ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-6ubuntu5.1","pocket":"security"},{"name":"libfreeimageplus-dev","version":"3.18.0+ds2-6ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-6ubuntu5.1","pocket":"security"},{"name":"libfreeimageplus-doc","version":"3.18.0+ds2-6ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-6ubuntu5.1","pocket":"security"},{"name":"libfreeimageplus3","version":"3.18.0+ds2-6ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-6ubuntu5.1","pocket":"security"}],"lunar":[{"name":"freeimage","version":"3.18.0+ds2-9ubuntu0.1","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.18.0+ds2-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9ubuntu0.1","pocket":"security"},{"name":"libfreeimage3","version":"3.18.0+ds2-9ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9ubuntu0.1","pocket":"security"},{"name":"libfreeimageplus-dev","version":"3.18.0+ds2-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9ubuntu0.1","pocket":"security"},{"name":"libfreeimageplus-doc","version":"3.18.0+ds2-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9ubuntu0.1","pocket":"security"},{"name":"libfreeimageplus3","version":"3.18.0+ds2-9ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9ubuntu0.1","pocket":"security"}],"mantic":[{"name":"freeimage","version":"3.18.0+ds2-9.1ubuntu0.1","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.18.0+ds2-9.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9.1ubuntu0.1","pocket":"security"},{"name":"libfreeimage3","version":"3.18.0+ds2-9.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9.1ubuntu0.1","pocket":"security"},{"name":"libfreeimageplus-dev","version":"3.18.0+ds2-9.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9.1ubuntu0.1","pocket":"security"},{"name":"libfreeimageplus-doc","version":"3.18.0+ds2-9.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9.1ubuntu0.1","pocket":"security"},{"name":"libfreeimageplus3","version":"3.18.0+ds2-9.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":"https://launchpad.net/ubuntu/+source/freeimage/3.18.0+ds2-9.1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"freeimage","version":"3.15.4-3ubuntu0.1+esm3","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.15.4-3ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-infra"},{"name":"libfreeimage3","version":"3.15.4-3ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"freeimage","version":"3.17.0+ds1-2ubuntu0.1+esm1","description":"Support library for graphics image formats","is_source":true},{"name":"libfreeimage-dev","version":"3.17.0+ds1-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimage3","version":"3.17.0+ds1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimageplus-dev","version":"3.17.0+ds1-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimageplus-doc","version":"3.17.0+ds1-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"},{"name":"libfreeimageplus3","version":"3.17.0+ds1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/freeimage","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-21427","CVE-2020-21428","CVE-2019-12213","CVE-2020-22524","CVE-2019-12211"]}]},{"id":"CVE-2020-22219","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:38.294066+00:00","description":"\nBuffer Overflow vulnerability in function bitwriter_grow_ in flac before\n1.4.0 allows remote attackers to run arbitrary code via crafted input to\nthe encoder.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6360-1","https://ubuntu.com/security/notices/USN-6360-2","https://www.cve.org/CVERecord?id=CVE-2020-22219"],"bugs":["https://github.com/xiph/flac/issues/215"],"patches":{"flac":["upstream: https://github.com/xiph/flac/commit/21fe95ee828b0b9b944f6aa0bb02d24fbb981815"]},"tags":{},"packages":[{"name":"flac","source":"https://ubuntu.com/security/cve?package=flac","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=flac","debian":"https://tracker.debian.org/pkg/flac","statuses":[{"release_codename":"focal","status":"released","description":"1.3.3-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.3.3-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.3.2-1ubuntu0.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.3.0-2ubuntu0.14.04.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.3.1-4ubuntu0.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"lunar","status":"not-affected","description":"1.4.2+ds-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.0","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.4.3+ds-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6360-1","USN-6360-2"],"notices":[{"id":"USN-6360-1","title":"FLAC vulnerability","summary":"FLAC could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-12T16:36:18.643334","description":"It was discovered that FLAC incorrectly handled encoding certain files. A\nremote attacker could use this issue to cause FLAC to crash, resulting in a\ndenial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"focal":[{"name":"flac","version":"1.3.3-1ubuntu0.2","description":"Free Lossless Audio Codec","is_source":true},{"name":"flac","version":"1.3.3-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-1ubuntu0.2","pocket":"security"},{"name":"libflac++-dev","version":"1.3.3-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-1ubuntu0.2","pocket":"security"},{"name":"libflac++6v5","version":"1.3.3-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-1ubuntu0.2","pocket":"security"},{"name":"libflac-dev","version":"1.3.3-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-1ubuntu0.2","pocket":"security"},{"name":"libflac-doc","version":"1.3.3-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-1ubuntu0.2","pocket":"security"},{"name":"libflac8","version":"1.3.3-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"flac","version":"1.3.3-2ubuntu0.2","description":"Free Lossless Audio Codec","is_source":true},{"name":"flac","version":"1.3.3-2ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-2ubuntu0.2","pocket":"security"},{"name":"libflac++-dev","version":"1.3.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-2ubuntu0.2","pocket":"security"},{"name":"libflac++6v5","version":"1.3.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-2ubuntu0.2","pocket":"security"},{"name":"libflac-dev","version":"1.3.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-2ubuntu0.2","pocket":"security"},{"name":"libflac-doc","version":"1.3.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-2ubuntu0.2","pocket":"security"},{"name":"libflac8","version":"1.3.3-2ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":"https://launchpad.net/ubuntu/+source/flac/1.3.3-2ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-22219"]},{"id":"USN-6360-2","title":"FLAC vulnerability","summary":"FLAC could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-22T00:31:34.963893","description":"USN-6360-1 fixed a vulnerability in FLAC. This update provides the\ncorresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and\nUbuntu 18.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that FLAC incorrectly handled encoding certain files. A\n remote attacker could use this issue to cause FLAC to crash, resulting in a\n denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"flac","version":"1.3.2-1ubuntu0.1+esm1","description":"Free Lossless Audio Codec","is_source":true},{"name":"flac","version":"1.3.2-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac++-dev","version":"1.3.2-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac++6v5","version":"1.3.2-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac-dev","version":"1.3.2-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac-doc","version":"1.3.2-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac8","version":"1.3.2-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"flac","version":"1.3.0-2ubuntu0.14.04.1+esm2","description":"Free Lossless Audio Codec","is_source":true},{"name":"flac","version":"1.3.0-2ubuntu0.14.04.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac++-dev","version":"1.3.0-2ubuntu0.14.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac++6","version":"1.3.0-2ubuntu0.14.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac-dev","version":"1.3.0-2ubuntu0.14.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac-doc","version":"1.3.0-2ubuntu0.14.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac8","version":"1.3.0-2ubuntu0.14.04.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"flac","version":"1.3.1-4ubuntu0.1~esm2","description":"Free Lossless Audio Codec","is_source":true},{"name":"flac","version":"1.3.1-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac++-dev","version":"1.3.1-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac++6v5","version":"1.3.1-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac-dev","version":"1.3.1-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac-doc","version":"1.3.1-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"},{"name":"libflac8","version":"1.3.1-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/flac","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-22219"]}]},{"id":"CVE-2020-22218","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:38.294066+00:00","description":"\nAn issue was discovered in function _libssh2_packet_add in libssh2 1.10.0\nallows attackers to access out of bounds memory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/libssh2/libssh2/pull/476","https://ubuntu.com/security/notices/USN-6371-1","https://www.cve.org/CVERecord?id=CVE-2020-22218"],"bugs":[""],"patches":{"libssh2":["upstream: https://github.com/libssh2/libssh2/commit/0b44e558f311671f6e6d14c559bc1c9bda59b8df"]},"tags":{},"packages":[{"name":"libssh2","source":"https://ubuntu.com/security/cve?package=libssh2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libssh2","debian":"https://tracker.debian.org/pkg/libssh2","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.8.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.8.0-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.10.0-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.10.0-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.4.3-2ubuntu0.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.5.0-2ubuntu0.1+esm2","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"not-affected","description":"1.10.0-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-6371-1"],"notices":[{"id":"USN-6371-1","title":"libssh2 vulnerability","summary":"libssh2 could be made to crash if it received specially\ncrafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-14T15:03:04.752794","description":"It was discovered that libssh2 incorrectly handled memory\naccess. An attacker could possibly use this issue to cause\na crash.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libssh2","version":"1.8.0-1ubuntu0.1","description":"Client-side C library implementing the SSH2 protocol","is_source":true},{"name":"libssh2-1","version":"1.8.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":"https://launchpad.net/ubuntu/+source/libssh2/1.8.0-1ubuntu0.1","pocket":"security"},{"name":"libssh2-1-dev","version":"1.8.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":"https://launchpad.net/ubuntu/+source/libssh2/1.8.0-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libssh2","version":"1.8.0-2.1ubuntu0.1","description":"Client-side C library implementing the SSH2 protocol","is_source":true},{"name":"libssh2-1","version":"1.8.0-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":"https://launchpad.net/ubuntu/+source/libssh2/1.8.0-2.1ubuntu0.1","pocket":"security"},{"name":"libssh2-1-dev","version":"1.8.0-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":"https://launchpad.net/ubuntu/+source/libssh2/1.8.0-2.1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"libssh2","version":"1.4.3-2ubuntu0.2+esm3","description":"Client-side C library implementing the SSH2 protocol","is_source":true},{"name":"libssh2-1","version":"1.4.3-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":null,"pocket":"esm-infra"},{"name":"libssh2-1-dev","version":"1.4.3-2ubuntu0.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libssh2","version":"1.5.0-2ubuntu0.1+esm2","description":"Client-side C library implementing the SSH2 protocol","is_source":true},{"name":"libssh2-1","version":"1.5.0-2ubuntu0.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":null,"pocket":"esm-apps"},{"name":"libssh2-1-dev","version":"1.5.0-2ubuntu0.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh2","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-22218"]}]},{"id":"CVE-2020-22217","published":"2023-08-22T19:16:00","updated_at":"2025-08-18T17:12:45.662661+00:00","description":"\nBuffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via\nfunction ares_parse_soa_reply in ares_parse_soa_reply.c.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOnly an out-of-bounds read, so denial of service only"}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6376-1","https://www.cve.org/CVERecord?id=CVE-2020-22217"],"bugs":["https://github.com/c-ares/c-ares/issues/333"],"patches":{"c-ares":["upstream: https://github.com/c-ares/c-ares/commit/1b98172b141fe874ad43e679e67506f9b2139043"]},"tags":{},"packages":[{"name":"c-ares","source":"https://ubuntu.com/security/cve?package=c-ares","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=c-ares","debian":"https://tracker.debian.org/pkg/c-ares","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.18.1-1ubuntu0.22.04.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.18.1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.15.0-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.19.1-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.19.1-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.19.1-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.19.1-3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.19.1-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.19.1-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6376-1"],"notices":[{"id":"USN-6376-1","title":"c-ares vulnerability","summary":"c-ares could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-18T13:08:11.897301","description":"It was discovered that c-ares incorrectly parsed certain SOA replies. A\nremote attacker could possibly use this issue to cause c-res to crash,\nresulting in a denial of service.\n","is_hidden":false,"release_packages":{"focal":[{"name":"c-ares","version":"1.15.0-1ubuntu0.4","description":"library for asynchronous name resolution","is_source":true},{"name":"libc-ares-dev","version":"1.15.0-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/c-ares","version_link":"https://launchpad.net/ubuntu/+source/c-ares/1.15.0-1ubuntu0.4","pocket":"security"},{"name":"libc-ares2","version":"1.15.0-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/c-ares","version_link":"https://launchpad.net/ubuntu/+source/c-ares/1.15.0-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-22217"]}]},{"id":"CVE-2020-21896","published":"2023-08-22T19:16:00","updated_at":"2025-10-17T10:04:09.713244+00:00","description":"\nA Use After Free vulnerability in svg_dev_text_span_as_paths_defs function\nin source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote\nattackers to cause a denial of service via opening of a crafted PDF file.","ubuntu_description":"","notes":[{"author":"shishirsub10","note":"mupdf in xenial does not have draw param"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.ghostscript.com/show_bug.cgi?id=701294","https://www.cve.org/CVERecord?id=CVE-2020-21896","http://www.ghostscript.com/cgi-bin/findgit.cgi?8719e07834d6a72b6b4131539e49ed1e8e2ff79e","https://ubuntu.com/security/notices/USN-7825-1"],"bugs":[""],"patches":{"mupdf":[]},"tags":{},"packages":[{"name":"mupdf","source":"https://ubuntu.com/security/cve?package=mupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mupdf","debian":"https://tracker.debian.org/pkg/mupdf","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.18.0","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.23.10+ds1-1build3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.25.1+ds1-5build2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.19.0+ds1-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.7a-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.25.1+ds1-6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.12.0+ds1-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.16.1+ds1-1ubuntu1+esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-7825-1"],"notices":[{"id":"USN-7825-1","title":"MuPDF vulnerabilities","summary":"Several security issues were fixed in MuPDF.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-10-16T03:05:55.737584","description":"It was discovered that MuPDF incorrectly managed memory, resulting in a\nmemory leak. An attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-1000036)\n\nIt was discovered that MuPDF could enter an infinite loop when parsing\ncertain PDF files. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2018-10289)\n\nIt was discovered that MuPDF incorrectly managed memory, possibly leading\nto a segmentation fault. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2018-16647, CVE-2018-16648)\n\nIt was discovered that MuPDF contained a use-after-free vulnerability.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2020-21896)\n\nIt was discovered that MuPDF incorrectly managed memory, resulting in a\nmemory leak. An attacker could possibly use this issue to cause a denial\nof service or obtain sensitive information. This issue only affected\nUbuntu 20.04 LTS. (CVE-2020-26683)\n\nMaxim Mishechkin, Vitalii Akolzin, Shamil Kurmangaleev, Denis Straghkov,\nFedor Nis'kov and Ivan Gulakov discovered that MuPDF incorrectly managed\nmemory under certain circumstances, leading to a double-free. An attacker\ncould possibly use this to cause a denial of service. This issue only\naffected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-3407)\n\nXuwei Liu discovered that MuPDF may perform an out-of-bounds write under\ncertain circumstances. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu\n20.04 LTS. (CVE-2021-37220)","is_hidden":false,"release_packages":{"bionic":[{"name":"mupdf","version":"1.12.0+ds1-1ubuntu0.1~esm1","description":"A lightweight open source software framework for viewing and converting PDF, XPS, and E-book documents","is_source":true},{"name":"libmupdf-dev","version":"1.12.0+ds1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"},{"name":"mupdf","version":"1.12.0+ds1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"},{"name":"mupdf-tools","version":"1.12.0+ds1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"mupdf","version":"1.16.1+ds1-1ubuntu1+esm1","description":"A lightweight open source software framework for viewing and converting PDF, XPS, and E-book documents","is_source":true},{"name":"libmupdf-dev","version":"1.16.1+ds1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"},{"name":"mupdf","version":"1.16.1+ds1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"},{"name":"mupdf-tools","version":"1.16.1+ds1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"mupdf","version":"1.7a-1ubuntu0.1~esm1","description":"A lightweight open source software framework for viewing and converting PDF, XPS, and E-book documents","is_source":true},{"name":"libmupdf-dev","version":"1.7a-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"},{"name":"mupdf","version":"1.7a-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"},{"name":"mupdf-tools","version":"1.7a-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mupdf","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-16647","CVE-2018-10289","CVE-2018-1000036","CVE-2018-16648","CVE-2020-26683","CVE-2021-37220","CVE-2021-3407","CVE-2020-21896"]}]},{"id":"CVE-2020-21890","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:29.755808+00:00","description":"\nBuffer Overflow vulnerability in clj_media_size function in\ndevices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to\ncause a denial of service or other unspecified impact(s) via opening of\ncrafted PDF document.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6364-1","https://www.cve.org/CVERecord?id=CVE-2020-21890"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=701846"],"patches":{"ghostscript":["upstream: https://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=494eeedf73d13fac5710e56f3a8fb2e7e2379d73"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"9.55.0~dfsg1-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"10.0.0~dfsg1-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.51, 9.51~dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"9.50~dfsg-5ubuntu4.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","component":null,"pocket":"esm-infra"},{"release_codename":"mantic","status":"not-affected","description":"10.01.2~dfsg1-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6364-1"],"notices":[{"id":"USN-6364-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-13T12:47:18.188635","description":"It was discovered that Ghostscript incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-21710)\n\nIt was discovered that Ghostscript incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service,\nor possibly execute arbitrary code. (CVE-2020-21890)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"ghostscript","version":"9.50~dfsg-5ubuntu4.10","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"ghostscript-doc","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"ghostscript-x","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"libgs-dev","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"libgs9","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"libgs9-common","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-21890","CVE-2020-21710"]}]},{"id":"CVE-2020-21724","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:44:03.979614+00:00","description":"\nBuffer Overflow vulnerability in ExtractorInformation function in\nstreamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run\narbitrary code via opening of crafted ogg file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/oggvideotools/bugs/9/","https://github.com/xiaoxiongwang/security/tree/master/oggvideotools#segv-and-heap-overflow-detected-in-line-17-of-streamextractorcpp","https://www.cve.org/CVERecord?id=CVE-2020-21724"],"bugs":[""],"patches":{"oggvideotools":[]},"tags":{},"packages":[{"name":"oggvideotools","source":"https://ubuntu.com/security/cve?package=oggvideotools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oggvideotools","debian":"https://tracker.debian.org/pkg/oggvideotools","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21723","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:44:03.979614+00:00","description":"\nA Segmentation Fault issue discovered StreamSerializer::extractStreams\nfunction in streamSerializer.cpp in oggvideotools 0.9.1 allows remote\nattackers to cause a denial of service (crash) via opening of crafted ogg\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/oggvideotools/bugs/10/","https://github.com/xiaoxiongwang/security/tree/master/oggvideotools#segv-occurs-in-function-streamserializerextractstreams-in-streamserializercpp","https://www.cve.org/CVERecord?id=CVE-2020-21723"],"bugs":[""],"patches":{"oggvideotools":[]},"tags":{},"packages":[{"name":"oggvideotools","source":"https://ubuntu.com/security/cve?package=oggvideotools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oggvideotools","debian":"https://tracker.debian.org/pkg/oggvideotools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21722","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:44:03.979614+00:00","description":"\nBuffer Overflow vulnerability in oggvideotools 0.9.1 allows remote\nattackers to run arbitrary code via opening of crafted ogg file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/xiaoxiongwang/security/tree/master/oggvideotools#segv-and-heap-use-after-free-detected-in-line-17-of-streamextractorcpp","https://sourceforge.net/p/oggvideotools/bugs/11/","https://www.cve.org/CVERecord?id=CVE-2020-21722"],"bugs":[""],"patches":{"oggvideotools":[]},"tags":{},"packages":[{"name":"oggvideotools","source":"https://ubuntu.com/security/cve?package=oggvideotools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oggvideotools","debian":"https://tracker.debian.org/pkg/oggvideotools","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21710","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:29.755808+00:00","description":"\nA divide by zero issue discovered in eps_print_page in gdevepsn.c in\nArtifex Software GhostScript 9.50 allows remote attackers to cause a denial\nof service via opening of crafted PDF file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6364-1","https://www.cve.org/CVERecord?id=CVE-2020-21710"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=701843"],"patches":{"ghostscript":["upstream: https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=f70ab2044429fe4b991801476ea3f4b4a5c0cdf4","upstream: https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=4e713293de84b689c4ab358f3e110ea54aa81925"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"9.55.0~dfsg1-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"10.0.0~dfsg1-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.51, 9.51~dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"9.50~dfsg-5ubuntu4.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","component":null,"pocket":"esm-infra"},{"release_codename":"mantic","status":"not-affected","description":"10.01.2~dfsg1-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6364-1"],"notices":[{"id":"USN-6364-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-13T12:47:18.188635","description":"It was discovered that Ghostscript incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-21710)\n\nIt was discovered that Ghostscript incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service,\nor possibly execute arbitrary code. (CVE-2020-21890)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.18.04.18+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"ghostscript","version":"9.50~dfsg-5ubuntu4.10","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"ghostscript-doc","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"ghostscript-x","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"libgs-dev","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"libgs9","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"},{"name":"libgs9-common","version":"9.50~dfsg-5ubuntu4.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.50~dfsg-5ubuntu4.10","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.16.04.14+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-21890","CVE-2020-21710"]}]},{"id":"CVE-2020-21699","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:29.755808+00:00","description":"\nThe web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru\n1.13.2 is vulnerable to an integer overflow vulnerability in the nginx\nrange filter module, resulting in the leakage of potentially sensitive\ninformation triggered by specially crafted requests.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This CVE only applies to the Tengine web server, which is a\nfork of nginx. The original nginx CVE was CVE-2017-7529."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/ZxDecide/Nginx-variants/blob/master/%E9%99%84%E4%BB%B6(Tengine).docx","https://www.cve.org/CVERecord?id=CVE-2020-21699"],"bugs":[""],"patches":{"nginx":[]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21687","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:43:59.855069+00:00","description":"\nBuffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0\nallows remote attackers to cause a denial of service via crafted asm file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.nasm.us/show_bug.cgi?id=3392645","https://www.cve.org/CVERecord?id=CVE-2020-21687"],"bugs":[""],"patches":{"nasm":[]},"tags":{},"packages":[{"name":"nasm","source":"https://ubuntu.com/security/cve?package=nasm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nasm","debian":"https://tracker.debian.org/pkg/nasm","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.13.02-0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.01-1build1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.14.02-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.15.05-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.11.08-1ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21686","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:43:59.855069+00:00","description":"\nA stack-use-after-scope issue discovered in expand_mmac_params function in\npreproc.c in nasm before 2.15.04 allows remote attackers to cause a denial\nof service via crafted asm file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.nasm.us/show_bug.cgi?id=3392643","https://www.cve.org/CVERecord?id=CVE-2020-21686"],"bugs":[""],"patches":{"nasm":[]},"tags":{},"packages":[{"name":"nasm","source":"https://ubuntu.com/security/cve?package=nasm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nasm","debian":"https://tracker.debian.org/pkg/nasm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.15.05-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.01-1build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21685","published":"2023-08-22T19:16:00","updated_at":"2025-09-16T01:33:52.688397+00:00","description":"\nBuffer Overflow vulnerability in hash_findi function in hashtbl.c in nasm\n2.15rc0 allows remote attackers to cause a denial of service via crafted\nasm file.","ubuntu_description":"","notes":[{"author":"octagalland","note":"Upstream closed the issue after failing to reproduce it with\nthe provided POC. We can't reproduce either."}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.nasm.us/show_bug.cgi?id=3392644","https://www.cve.org/CVERecord?id=CVE-2020-21685"],"bugs":[""],"patches":{"nasm":[]},"tags":{},"packages":[{"name":"nasm","source":"https://ubuntu.com/security/cve?package=nasm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nasm","debian":"https://tracker.debian.org/pkg/nasm","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21679","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:25.685361+00:00","description":"\nBuffer Overflow vulnerability in WritePCXImage function in pcx.c in\nGraphicsMagick 1.4 allows remote attackers to cause a denial of service via\nconverting of crafted image file to pcx format.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/graphicsmagick/bugs/619/","https://www.cve.org/CVERecord?id=CVE-2020-21679"],"bugs":[""],"patches":{"graphicsmagick":["upstream: https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/bd13b1d335f3"]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was not-affected","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was not-affected","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21583","published":"2023-08-22T19:16:00","updated_at":"2025-08-26T12:21:32.264053+00:00","description":"\nAn issue was discovered in hwclock.13-v2.27 allows attackers to gain\nescalated privlidges or execute arbitrary commands via the path parameter\nwhen setting the date.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nNon-default and improbable configuration"},{"author":"mdeslaur","note":"This is only an issue when hwclock was modified by the\nadministrator to be setuid root, which should never be done.\nUbuntu packages are not shipped with the setuid bit set.\nTo prevent misconfiguration, version 2.27 now prevent it from\nbeing run setuid."}],"codename":null,"priority":"low","cvss3":6.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://packetstormsecurity.com/files/132061/hwclock-Privilege-Escalation.html","https://www.cve.org/CVERecord?id=CVE-2020-21583"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=786804"],"patches":{"util-linux":["upstream: https://github.com/util-linux/util-linux/commit/687cc5d58942b24a9f4013c68876d8cbea907ab1"]},"tags":{},"packages":[{"name":"util-linux","source":"https://ubuntu.com/security/cve?package=util-linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=util-linux","debian":"https://tracker.debian.org/pkg/util-linux","statuses":[{"release_codename":"xenial","status":"not-affected","description":"2.27.1-6ubuntu3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21528","published":"2023-08-22T19:16:00","updated_at":"2025-07-11T07:43:59.855069+00:00","description":"\nA Segmentation Fault issue discovered in in ieee_segment function in\noutieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a\ndenial of service via crafted assembly file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.nasm.us/show_bug.cgi?id=3392637","https://www.cve.org/CVERecord?id=CVE-2020-21528"],"bugs":[""],"patches":{"nasm":[]},"tags":{},"packages":[{"name":"nasm","source":"https://ubuntu.com/security/cve?package=nasm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nasm","debian":"https://tracker.debian.org/pkg/nasm","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.13.02-0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.01-1build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.11.08-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.16.03-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21490","published":"2023-08-22T19:16:00","updated_at":"2025-08-25T23:23:16.953895+00:00","description":"\nAn issue was discovered in GNU Binutils 2.34. It is a memory leak when\nprocess microblaze-dis.c. This one will consume memory on each insn\ndisassembled.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"binutils isn't safe for untrusted inputs."}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=25249","https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=378fd436405b3051df34ac995b2e03fe1f3d1907","https://ubuntu.com/security/notices/USN-6381-1","https://www.cve.org/CVERecord?id=CVE-2020-21490"],"bugs":[""],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=378fd436405b3051df34ac995b2e03fe1f3d1907"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"bionic","status":"released","description":"2.30-21ubuntu1~18.04.9+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"not-affected","description":"2.34-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.38-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.40-2ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.34","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.24-5ubuntu14.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm7","component":null,"pocket":"esm-infra"},{"release_codename":"mantic","status":"not-affected","description":"2.41-4ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6381-1"],"notices":[{"id":"USN-6381-1","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-09-18T18:52:10.069063","description":"It was discovered that a memory leak existed in certain GNU binutils\nmodules. An attacker could possibly use this issue to cause a denial of\nservice (memory exhaustion). (CVE-2020-19724, CVE-2020-21490)\n\nIt was discovered that GNU binutils was not properly performing bounds\nchecks in several functions, which could lead to a buffer overflow. An\nattacker could possibly use this issue to cause a denial of service,\nexpose sensitive information or execute arbitrary code.\n(CVE-2020-19726, CVE-2021-46174, CVE-2022-45703)\n\nIt was discovered that GNU binutils was not properly initializing heap\nmemory when processing certain print instructions. An attacker could\npossibly use this issue to expose sensitive information. (CVE-2020-35342)\n\nIt was discovered that GNU binutils was not properly handling the logic\nbehind certain memory management related operations, which could lead to a\nbuffer overflow. An attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code. (CVE-2022-44840)\n\nIt was discovered that GNU binutils was not properly handling the logic\nbehind certain memory management related operations, which could lead to\nan invalid memory access. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2022-47695)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"binutils","version":"2.30-21ubuntu1~18.04.9+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-common","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-for-build","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-for-host","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-i686-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-i686-kfreebsd-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-i686-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-ia64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsisa32r6-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsisa32r6el-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsisa64r6-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsisa64r6-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsisa64r6el-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsisa64r6el-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-riscv64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-x86-64-kfreebsd-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-x86-64-linux-gnu","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-x86-64-linux-gnux32","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"libbinutils","version":"2.30-21ubuntu1~18.04.9+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"binutils","version":"2.24-5ubuntu14.2+esm3","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-static","version":"2.24-5ubuntu14.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm7","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-19726","CVE-2020-35342","CVE-2022-44840","CVE-2020-21490","CVE-2022-45703","CVE-2021-46174","CVE-2020-19724","CVE-2022-47695"]}]}],"offset":33760,"limit":20,"total_results":79316}