{"cves":[{"id":"CVE-2022-43239","published":"2022-11-02T14:15:00","updated_at":"2025-08-25T23:58:57.825019+00:00","description":"\nLibde265 v1.0.8 was discovered to contain a heap-buffer-overflow\nvulnerability via mc_chroma<unsigned short> in motion.cc. This\nvulnerability allows attackers to cause a Denial of Service (DoS) via a\ncrafted video file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/strukturag/libde265/issues/341","https://ubuntu.com/security/notices/USN-6627-1","https://www.cve.org/CVERecord?id=CVE-2022-43239"],"bugs":[""],"patches":{"libde265":[]},"tags":{},"packages":[{"name":"libde265","source":"https://ubuntu.com/security/cve?package=libde265","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libde265","debian":"https://tracker.debian.org/pkg/libde265","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2-2ubuntu0.18.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.0.4-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.0.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2-2ubuntu0.16.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6627-1"],"notices":[{"id":"USN-6627-1","title":"libde265 vulnerabilities","summary":"Several security issues were fixed in libde265.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-02-08T13:48:22.086568","description":"It was discovered that libde265 could be made to read out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,\nCVE-2022-43242)\n\nIt was discovered that libde265 did not properly manage memory. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2021-36408) \n\nIt was discovered that libde265 contained a logical error. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2021-36409)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. (CVE-2021-36410, CVE-2022-43235,\nCVE-2022-43236, CVE-2022-43237, CVE-2022-43239, CVE-2022-43240,\nCVE-2022-43243, CVE-2022-43248, CVE-2022-43252, CVE-2022-43253)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-1253)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libde265","version":"1.0.2-2ubuntu0.18.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libde265","version":"1.0.4-1ubuntu0.2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-dev","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-examples","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"libde265","version":"1.0.8-1ubuntu0.1","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-dev","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-examples","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libde265","version":"1.0.2-2ubuntu0.16.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-43242","CVE-2022-43243","CVE-2021-36409","CVE-2021-36410","CVE-2022-43240","CVE-2022-43239","CVE-2022-43237","CVE-2021-36411","CVE-2022-1253","CVE-2022-43236","CVE-2022-43253","CVE-2022-43241","CVE-2022-43235","CVE-2021-35452","CVE-2021-36408","CVE-2022-43252","CVE-2022-43238","CVE-2022-43248"]}]},{"id":"CVE-2022-43238","published":"2022-11-02T14:15:00","updated_at":"2025-08-25T23:58:57.825019+00:00","description":"\nLibde265 v1.0.8 was discovered to contain an unknown crash via\nff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This vulnerability\nallows attackers to cause a Denial of Service (DoS) via a crafted video\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/strukturag/libde265/issues/336","https://ubuntu.com/security/notices/USN-6627-1","https://www.cve.org/CVERecord?id=CVE-2022-43238"],"bugs":[""],"patches":{"libde265":[]},"tags":{},"packages":[{"name":"libde265","source":"https://ubuntu.com/security/cve?package=libde265","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libde265","debian":"https://tracker.debian.org/pkg/libde265","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2-2ubuntu0.18.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.0.4-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.0.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2-2ubuntu0.16.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6627-1"],"notices":[{"id":"USN-6627-1","title":"libde265 vulnerabilities","summary":"Several security issues were fixed in libde265.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-02-08T13:48:22.086568","description":"It was discovered that libde265 could be made to read out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,\nCVE-2022-43242)\n\nIt was discovered that libde265 did not properly manage memory. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2021-36408) \n\nIt was discovered that libde265 contained a logical error. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2021-36409)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. (CVE-2021-36410, CVE-2022-43235,\nCVE-2022-43236, CVE-2022-43237, CVE-2022-43239, CVE-2022-43240,\nCVE-2022-43243, CVE-2022-43248, CVE-2022-43252, CVE-2022-43253)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-1253)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libde265","version":"1.0.2-2ubuntu0.18.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libde265","version":"1.0.4-1ubuntu0.2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-dev","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-examples","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"libde265","version":"1.0.8-1ubuntu0.1","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-dev","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-examples","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libde265","version":"1.0.2-2ubuntu0.16.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-43242","CVE-2022-43243","CVE-2021-36409","CVE-2021-36410","CVE-2022-43240","CVE-2022-43239","CVE-2022-43237","CVE-2021-36411","CVE-2022-1253","CVE-2022-43236","CVE-2022-43253","CVE-2022-43241","CVE-2022-43235","CVE-2021-35452","CVE-2021-36408","CVE-2022-43252","CVE-2022-43238","CVE-2022-43248"]}]},{"id":"CVE-2022-43237","published":"2022-11-02T14:15:00","updated_at":"2025-08-25T23:58:57.825019+00:00","description":"\nLibde265 v1.0.8 was discovered to contain a stack-buffer-overflow\nvulnerability via void put_epel_hv_fallback<unsigned short> in\nfallback-motion.cc. This vulnerability allows attackers to cause a Denial\nof Service (DoS) via a crafted video file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/strukturag/libde265/issues/344","https://ubuntu.com/security/notices/USN-6627-1","https://www.cve.org/CVERecord?id=CVE-2022-43237"],"bugs":[""],"patches":{"libde265":[]},"tags":{},"packages":[{"name":"libde265","source":"https://ubuntu.com/security/cve?package=libde265","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libde265","debian":"https://tracker.debian.org/pkg/libde265","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2-2ubuntu0.18.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.0.4-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.0.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2-2ubuntu0.16.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6627-1"],"notices":[{"id":"USN-6627-1","title":"libde265 vulnerabilities","summary":"Several security issues were fixed in libde265.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-02-08T13:48:22.086568","description":"It was discovered that libde265 could be made to read out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,\nCVE-2022-43242)\n\nIt was discovered that libde265 did not properly manage memory. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2021-36408) \n\nIt was discovered that libde265 contained a logical error. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2021-36409)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. (CVE-2021-36410, CVE-2022-43235,\nCVE-2022-43236, CVE-2022-43237, CVE-2022-43239, CVE-2022-43240,\nCVE-2022-43243, CVE-2022-43248, CVE-2022-43252, CVE-2022-43253)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-1253)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libde265","version":"1.0.2-2ubuntu0.18.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libde265","version":"1.0.4-1ubuntu0.2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-dev","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-examples","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"libde265","version":"1.0.8-1ubuntu0.1","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-dev","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-examples","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libde265","version":"1.0.2-2ubuntu0.16.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-43242","CVE-2022-43243","CVE-2021-36409","CVE-2021-36410","CVE-2022-43240","CVE-2022-43239","CVE-2022-43237","CVE-2021-36411","CVE-2022-1253","CVE-2022-43236","CVE-2022-43253","CVE-2022-43241","CVE-2022-43235","CVE-2021-35452","CVE-2021-36408","CVE-2022-43252","CVE-2022-43238","CVE-2022-43248"]}]},{"id":"CVE-2022-43236","published":"2022-11-02T14:15:00","updated_at":"2025-08-25T23:58:53.596476+00:00","description":"\nLibde265 v1.0.8 was discovered to contain a stack-buffer-overflow\nvulnerability via put_qpel_fallback<unsigned short> in fallback-motion.cc.\nThis vulnerability allows attackers to cause a Denial of Service (DoS) via\na crafted video file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/strukturag/libde265/issues/343","https://ubuntu.com/security/notices/USN-6627-1","https://www.cve.org/CVERecord?id=CVE-2022-43236"],"bugs":[""],"patches":{"libde265":[]},"tags":{},"packages":[{"name":"libde265","source":"https://ubuntu.com/security/cve?package=libde265","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libde265","debian":"https://tracker.debian.org/pkg/libde265","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2-2ubuntu0.18.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.0.4-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.0.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2-2ubuntu0.16.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6627-1"],"notices":[{"id":"USN-6627-1","title":"libde265 vulnerabilities","summary":"Several security issues were fixed in libde265.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-02-08T13:48:22.086568","description":"It was discovered that libde265 could be made to read out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,\nCVE-2022-43242)\n\nIt was discovered that libde265 did not properly manage memory. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2021-36408) \n\nIt was discovered that libde265 contained a logical error. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2021-36409)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. (CVE-2021-36410, CVE-2022-43235,\nCVE-2022-43236, CVE-2022-43237, CVE-2022-43239, CVE-2022-43240,\nCVE-2022-43243, CVE-2022-43248, CVE-2022-43252, CVE-2022-43253)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-1253)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libde265","version":"1.0.2-2ubuntu0.18.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libde265","version":"1.0.4-1ubuntu0.2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-dev","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-examples","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"libde265","version":"1.0.8-1ubuntu0.1","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-dev","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-examples","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libde265","version":"1.0.2-2ubuntu0.16.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-43242","CVE-2022-43243","CVE-2021-36409","CVE-2021-36410","CVE-2022-43240","CVE-2022-43239","CVE-2022-43237","CVE-2021-36411","CVE-2022-1253","CVE-2022-43236","CVE-2022-43253","CVE-2022-43241","CVE-2022-43235","CVE-2021-35452","CVE-2021-36408","CVE-2022-43252","CVE-2022-43238","CVE-2022-43248"]}]},{"id":"CVE-2022-43235","published":"2022-11-02T14:15:00","updated_at":"2025-08-25T23:58:53.596476+00:00","description":"\nLibde265 v1.0.8 was discovered to contain a heap-buffer-overflow\nvulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in sse-motion.cc. This\nvulnerability allows attackers to cause a Denial of Service (DoS) via a\ncrafted video file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/strukturag/libde265/issues/337","https://ubuntu.com/security/notices/USN-6627-1","https://www.cve.org/CVERecord?id=CVE-2022-43235"],"bugs":[""],"patches":{"libde265":[]},"tags":{},"packages":[{"name":"libde265","source":"https://ubuntu.com/security/cve?package=libde265","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libde265","debian":"https://tracker.debian.org/pkg/libde265","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2-2ubuntu0.18.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.0.4-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.0.8-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2-2ubuntu0.16.04.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6627-1"],"notices":[{"id":"USN-6627-1","title":"libde265 vulnerabilities","summary":"Several security issues were fixed in libde265.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-02-08T13:48:22.086568","description":"It was discovered that libde265 could be made to read out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2021-35452, CVE-2021-36411, CVE-2022-43238, CVE-2022-43241,\nCVE-2022-43242)\n\nIt was discovered that libde265 did not properly manage memory. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2021-36408) \n\nIt was discovered that libde265 contained a logical error. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2021-36409)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. (CVE-2021-36410, CVE-2022-43235,\nCVE-2022-43236, CVE-2022-43237, CVE-2022-43239, CVE-2022-43240,\nCVE-2022-43243, CVE-2022-43248, CVE-2022-43252, CVE-2022-43253)\n\nIt was discovered that libde265 could be made to write out of bounds. If a\nuser or automated system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-1253)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libde265","version":"1.0.2-2ubuntu0.18.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.18.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libde265","version":"1.0.4-1ubuntu0.2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-dev","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"},{"name":"libde265-examples","version":"1.0.4-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.4-1ubuntu0.2","pocket":"security"}],"jammy":[{"name":"libde265","version":"1.0.8-1ubuntu0.1","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-dev","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"},{"name":"libde265-examples","version":"1.0.8-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":"https://launchpad.net/ubuntu/+source/libde265/1.0.8-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libde265","version":"1.0.2-2ubuntu0.16.04.1~esm2","description":"Open H.265 video codec implementation","is_source":true},{"name":"libde265-0","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-dev","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"},{"name":"libde265-examples","version":"1.0.2-2ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libde265","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-43242","CVE-2022-43243","CVE-2021-36409","CVE-2021-36410","CVE-2022-43240","CVE-2022-43239","CVE-2022-43237","CVE-2021-36411","CVE-2022-1253","CVE-2022-43236","CVE-2022-43253","CVE-2022-43241","CVE-2022-43235","CVE-2021-35452","CVE-2021-36408","CVE-2022-43252","CVE-2022-43238","CVE-2022-43248"]}]},{"id":"CVE-2022-3810","published":"2022-11-02T13:15:00","updated_at":"2025-07-11T07:52:03.988896+00:00","description":"\nA vulnerability was found in Axiomatic Bento4. It has been classified as\nproblematic. This affects the function AP4_File::AP4_File of the file\nMp42Hevc.cpp of the component mp42hevc. The manipulation leads to denial of\nservice. It is possible to initiate the attack remotely. The exploit has\nbeen disclosed to the public and may be used. The associated identifier of\nthis vulnerability is VDB-212667.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3810"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3809","published":"2022-11-02T13:15:00","updated_at":"2025-07-11T07:52:03.988896+00:00","description":"\nA vulnerability was found in Axiomatic Bento4 and classified as\nproblematic. Affected by this issue is the function ParseCommandLine of the\nfile Mp4Tag/Mp4Tag.cpp of the component mp4tag. The manipulation leads to\ndenial of service. The attack may be launched remotely. The exploit has\nbeen disclosed to the public and may be used. VDB-212666 is the identifier\nassigned to this vulnerability.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3809"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-37789","published":"2022-11-02T13:15:00","updated_at":"2025-07-11T07:47:51.315124+00:00","description":"\nstb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading\nto Information Disclosure or Denial of Service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/nothings/stb/issues/1178","https://www.cve.org/CVERecord?id=CVE-2021-37789"],"bugs":[""],"patches":{"libstb":[]},"tags":{},"packages":[{"name":"libstb","source":"https://ubuntu.com/security/cve?package=libstb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libstb","debian":"https://tracker.debian.org/pkg/libstb","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42919","published":"2022-11-02T00:00:00","updated_at":"2026-04-23T10:41:16.319387+00:00","description":"\nPython 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local\nprivilege escalation in a non-default configuration. The Python\nmultiprocessing library, when used with the forkserver start method on\nLinux, allows pickles to be deserialized from any user in the same machine\nlocal network namespace, which in many system configurations means any user\non the same machine. Pickles can execute arbitrary code. Thus, this allows\nfor local user privilege escalation to the user that any forkserver process\nis running as. Setting multiprocessing.util.abstract_sockets_supported to\nFalse is a workaround. The forkserver start method for multiprocessing is\nnot the default start method. This issue is Linux specific because only\nLinux supports abstract namespace sockets. CPython before 3.9 does not make\nuse of Linux abstract namespace sockets by default. Support for users\nmanually specifying an abstract namespace socket was added as a bugfix in\n3.7.8 and 3.8.3, but users would need to make specific uncommon API calls\nin order to do that in CPython before 3.9.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://python-security.readthedocs.io/vuln/multiprocessing-abstract-socket.html","https://ubuntu.com/security/notices/USN-5713-1","https://ubuntu.com/security/notices/USN-5888-1","https://www.cve.org/CVERecord?id=CVE-2022-42919","https://ubuntu.com/security/notices/USN-6891-1"],"bugs":["https://github.com/python/cpython/issues/97514"],"patches":{"python2.7":[],"python3.4":[],"python3.5":[],"python3.6":[],"python3.7":[],"python3.8":[],"python3.9":["upstream: https://github.com/python/cpython/commit/b43496c01a554cf41ae654a0379efae18609ad39"],"python3.10":["upstream: https://github.com/python/cpython/commit/eae692eed18892309bcc25a2c0f8980038305ea2"],"python3.11":["upstream: https://github.com/python/cpython/commit/4c0c1e201a896ee5141df9a698e8a94aad2d5e6d"]},"tags":{},"packages":[{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.10","source":"https://ubuntu.com/security/cve?package=python3.10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.10","debian":"https://tracker.debian.org/pkg/python3.10","statuses":[{"release_codename":"jammy","status":"released","description":"3.10.6-1~22.04.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.10.7-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.10.20","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.11","source":"https://ubuntu.com/security/cve?package=python3.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.11","debian":"https://tracker.debian.org/pkg/python3.11","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.11.0~rc1-1~22.04.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.11.0-3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.11.0-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.11.15","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.4","source":"https://ubuntu.com/security/cve?package=python3.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.4","debian":"https://tracker.debian.org/pkg/python3.4","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"python3.5","source":"https://ubuntu.com/security/cve?package=python3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.5","debian":"https://tracker.debian.org/pkg/python3.5","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"python3.6","source":"https://ubuntu.com/security/cve?package=python3.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.6","debian":"https://tracker.debian.org/pkg/python3.6","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.7","source":"https://ubuntu.com/security/cve?package=python3.7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.7","debian":"https://tracker.debian.org/pkg/python3.7","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.8","source":"https://ubuntu.com/security/cve?package=python3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.8","debian":"https://tracker.debian.org/pkg/python3.8","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.9","source":"https://ubuntu.com/security/cve?package=python3.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.9","debian":"https://tracker.debian.org/pkg/python3.9","statuses":[{"release_codename":"focal","status":"released","description":"3.9.5-3ubuntu0~20.04.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.9.25","component":null,"pocket":"security"}]}],"notices_ids":["USN-5713-1","USN-5888-1","USN-6891-1"],"notices":[{"id":"USN-5713-1","title":"Python vulnerability","summary":"Python could be made to run programs if it received specially crafted\nsocket connections.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-11-03T13:56:06.344745","description":"Devin Jeanpierre discovered that Python incorrectly handled sockets when\nthe multiprocessing module was being used. A local attacker could possibly\nuse this issue to execute arbitrary code and escalate privileges.\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"python3.10","version":"3.10.7-1ubuntu0.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"libpython3.10-minimal","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"idle-python3.10","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-doc","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-minimal","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-examples","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"libpython3.10","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"libpython3.10-dev","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"libpython3.10-testsuite","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-dev","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"libpython3.10-stdlib","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-venv","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-nopie","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"},{"name":"python3.10-full","version":"3.10.7-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.7-1ubuntu0.1","pocket":"security"}],"jammy":[{"name":"python3.10","version":"3.10.6-1~22.04.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"libpython3.10-minimal","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"idle-python3.10","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-doc","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-minimal","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-examples","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"libpython3.10","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"libpython3.10-dev","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"libpython3.10-testsuite","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-dev","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"libpython3.10-stdlib","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-venv","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-nopie","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"},{"name":"python3.10-full","version":"3.10.6-1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.6-1~22.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-42919"]},{"id":"USN-5888-1","title":"Python vulnerabilities","summary":"Several security issues were fixed in Python.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-02-27T17:08:31.229248","description":"It was discovered that Python incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially\ncrafted input file, a remote attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2015-20107)\n\nHamza Avvan discovered that Python incorrectly handled certain inputs. If a\nuser or an automated system were tricked into running a specially\ncrafted input, a remote attacker could possibly use this issue to execute\narbitrary code. (CVE-2021-28861)\n\nIt was discovered that Python incorrectly handled certain inputs. If a\nuser or an automated system were tricked into running a specially\ncrafted input, a remote attacker could possibly use this issue to execute\narbitrary code. (CVE-2022-37454, CVE-2022-42919)\n\nIt was discovered that Python incorrectly handled certain inputs. If a\nuser or an automated system were tricked into running a specially\ncrafted input, a remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2022-45061, CVE-2023-24329)\n","is_hidden":false,"release_packages":{"focal":[{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.9-dev","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-examples","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-full","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-venv","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-doc","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-dev","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"idle-python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-testsuite","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-stdlib","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-42919","CVE-2022-37454","CVE-2021-28861","CVE-2022-45061","CVE-2015-20107","CVE-2023-24329"]},{"id":"USN-6891-1","title":"Python vulnerabilities","summary":"Several security issues were fixed in Python.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-07-11T11:54:39.304153","description":"It was discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2015-20107)\n\nIt was discovered that Python incorrectly used regular expressions\nvulnerable to catastrophic backtracking. A remote attacker could possibly\nuse this issue to cause a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)\n\nIt was discovered that Python failed to initialize Expat’s hash salt. A\nremote attacker could possibly use this issue to cause hash collisions,\nleading to a denial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2018-14647)\n\nIt was discovered that Python incorrectly handled certain pickle files. An\nattacker could possibly use this issue to consume memory, leading to a\ndenial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2018-20406)\n\nIt was discovered that Python incorrectly validated the domain when\nhandling cookies. An attacker could possibly trick Python into sending\ncookies to the wrong domain. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2018-20852)\n\nJonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly\nhandled Unicode encoding during NFKC normalization. An attacker could\npossibly use this issue to obtain sensitive information. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2019-9636, CVE-2019-10160)\n\nIt was discovered that Python incorrectly parsed certain email addresses. A\nremote attacker could possibly use this issue to trick Python applications\ninto accepting email addresses that should be denied. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2019-16056)\n\nIt was discovered that the Python documentation XML-RPC server incorrectly\nhandled certain fields. A remote attacker could use this issue to execute a\ncross-site scripting (XSS) attack. This issue only affected Ubuntu 14.04\nLTS. (CVE-2019-16935)\n\nIt was discovered that Python documentation had a misleading information.\nA security issue could be possibly caused by wrong assumptions of this\ninformation. This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04\nLTS. (CVE-2019-17514)\n\nIt was discovered that Python incorrectly stripped certain characters from\nrequests. A remote attacker could use this issue to perform CRLF injection.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2019-18348)\n\nIt was discovered that Python incorrectly handled certain TAR archives.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2019-20907)\n\nColin Read and Nicolas Edet discovered that Python incorrectly handled\nparsing certain X509 certificates. An attacker could possibly use this\nissue to cause Python to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2019-5010)\n\nIt was discovered that incorrectly handled certain ZIP files. An attacker\ncould possibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2019-9674)\n\nIt was discovered that Python incorrectly handled certain urls. A remote\nattacker could possibly use this issue to perform CRLF injection attacks.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2019-9740, CVE-2019-9947)\n\nSihoon Lee discovered that Python incorrectly handled the local_file:\nscheme. A remote attacker could possibly use this issue to bypass blocklist\nmeschanisms. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-9948)\n\nIt was discovered that Python incorrectly handled certain IP values.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2020-14422)\n\nIt was discovered that Python incorrectly handled certain character\nsequences. A remote attacker could possibly use this issue to perform\nCRLF injection. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n18.04 LTS. (CVE-2020-26116)\n\nIt was discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code\nor cause a denial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2020-27619, CVE-2021-3177)\n\nIt was discovered that Python incorrectly handled certain HTTP requests.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2020-8492)\n\nIt was discovered that the Python stdlib ipaddress API incorrectly handled\noctal strings. A remote attacker could possibly use this issue to perform a\nwide variety of attacks, including bypassing certain access restrictions.\nThis issue only affected Ubuntu 18.04 LTS. (CVE-2021-29921)\n\nDavid Schwörer discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to expose sensitive information.\nThis issue only affected Ubuntu 18.04 LTS. (CVE-2021-3426)\n\nIt was discovered that Python incorrectly handled certain RFCs.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2021-3733)\n\nIt was discovered that Python incorrectly handled certain server\nresponses. An attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-3737)\n\nIt was discovered that Python incorrectly handled certain FTP requests.\nAn attacker could possibly use this issue to expose sensitive information.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2021-4189)\n\nIt was discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2022-0391)\n\nDevin Jeanpierre discovered that Python incorrectly handled sockets when\nthe multiprocessing module was being used. A local attacker could possibly\nuse this issue to execute arbitrary code and escalate privileges.\nThis issue only affected Ubuntu 22.04 LTS. (CVE-2022-42919)\n\nIt was discovered that Python incorrectly handled certain inputs. If a\nuser or an automated system were tricked into running a specially\ncrafted input, a remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 14.04 LTS,\nUbuntu 18.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-45061, CVE-2023-24329)\n\nIt was discovered that Python incorrectly handled certain scripts.\nAn attacker could possibly use this issue to execute arbitrary code\nor cause a crash. This issue only affected Ubuntu 14.04 LTS and\nUbuntu 18.04 LTS. (CVE-2022-48560)\n\nIt was discovered that Python incorrectly handled certain plist files.\nIf a user or an automated system were tricked into processing a specially\ncrafted plist file, an attacker could possibly use this issue to consume\nresources, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 18.04 LTS. (CVE-2022-48564)\n\nIt was discovered that Python did not properly handle XML entity\ndeclarations in plist files. An attacker could possibly use this\nvulnerability to perform an XML External Entity (XXE) injection,\nresulting in a denial of service or information disclosure. This issue\nonly affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS. (CVE-2022-48565)\n\nIt was discovered that Python did not properly provide constant-time\nprocessing for a crypto operation. An attacker could possibly use this\nissue to perform a timing attack and recover sensitive information. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2022-48566)\n\nIt was discovered that Python instances of ssl.SSLSocket were vulnerable\nto a bypass of the TLS handshake. An attacker could possibly use this\nissue to cause applications to treat unauthenticated received data before\nTLS handshake as authenticated data after TLS handshake. This issue only\naffected Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu\n22.04 LTS. (CVE-2023-40217)\n\nIt was discovered that Python incorrectly handled null bytes when\nnormalizing pathnames. An attacker could possibly use this issue to bypass\ncertain filename checks. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2023-41105)\n\nIt was discovered that Python incorrectly handled privilege with certain\nparameters. An attacker could possibly use this issue to maintain the\noriginal processes' groups before starting the new process. This issue\nonly affected Ubuntu 23.10. (CVE-2023-6507)\n\nIt was discovered that Python incorrectly handled symlinks in temp files.\nAn attacker could possibly use this issue to modify the permissions of\nfiles. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS and Ubuntu 23.10. (CVE-2023-6597)\n\nIt was discovered that Python incorrectly handled certain crafted zip\nfiles. An attacker could possibly use this issue to crash the program,\nresulting in a denial of service. (CVE-2024-0450)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"idle-python3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"idle-python3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-dev","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-minimal","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-stdlib","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-testsuite","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-dev","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-minimal","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-stdlib","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-testsuite","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-dev","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-minimal","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-stdlib","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-testsuite","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-dev","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-doc","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-examples","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-minimal","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-venv","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-dev","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-doc","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-examples","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-minimal","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-venv","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-dev","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-examples","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-minimal","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-venv","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"python3.8","version":"3.8.10-0ubuntu1~20.04.10","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.8","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"idle-python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-dev","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-minimal","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-stdlib","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-testsuite","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-dev","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-stdlib","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-testsuite","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.8","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-dev","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-doc","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-examples","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-full","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-minimal","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-venv","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-dev","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-doc","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-examples","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-full","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-venv","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"python3.10","version":"3.10.12-1~22.04.4","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.11","version":"3.11.0~rc1-1~22.04.1~esm1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.10","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"idle-python3.11","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.10","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-dev","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-minimal","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-stdlib","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-testsuite","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.11","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-dev","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-minimal","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-stdlib","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-testsuite","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.10","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-dev","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-doc","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-examples","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-full","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-minimal","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-nopie","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-venv","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.11","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-dev","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-doc","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-examples","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-full","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-minimal","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-nopie","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-venv","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"}],"mantic":[{"name":"python3.11","version":"3.11.6-3ubuntu0.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.12","version":"3.12.0-1ubuntu0.1","description":"Interactive high-level object-oriented language (version 3.12)","is_source":true},{"name":"idle-python3.11","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"idle-python3.12","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.11","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-dev","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-minimal","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-stdlib","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-testsuite","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.12","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-dev","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-minimal","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-stdlib","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-testsuite","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.11","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-dev","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-doc","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-examples","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-full","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-minimal","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-nopie","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-venv","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.12","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-dev","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-doc","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-examples","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-full","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-minimal","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-nopie","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-venv","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-dev","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-minimal","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-stdlib","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-testsuite","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-dev","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-doc","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-examples","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-minimal","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-venv","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-dev","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-minimal","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-stdlib","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-testsuite","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-dev","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-doc","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-examples","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-minimal","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-venv","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-29921","CVE-2021-3733","CVE-2022-48560","CVE-2019-5010","CVE-2020-26116","CVE-2019-16056","CVE-2019-16935","CVE-2018-14647","CVE-2018-20406","CVE-2019-10160","CVE-2015-20107","CVE-2020-27619","CVE-2022-48564","CVE-2021-4189","CVE-2022-0391","CVE-2019-17514","CVE-2019-9740","CVE-2023-6507","CVE-2019-18348","CVE-2018-20852","CVE-2018-1061","CVE-2019-9674","CVE-2019-9636","CVE-2020-8492","CVE-2019-20907","CVE-2019-9947","CVE-2023-41105","CVE-2023-6597","CVE-2021-3737","CVE-2022-48566","CVE-2018-1060","CVE-2022-45061","CVE-2023-40217","CVE-2022-42919","CVE-2022-48565","CVE-2024-0450","CVE-2019-9948","CVE-2020-14422","CVE-2021-3426","CVE-2021-3177","CVE-2023-24329"]}]},{"id":"CVE-2022-3723","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:16.045849+00:00","description":"\nType confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3723","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3661","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:07.128403+00:00","description":"\nInsufficient data validation in Extensions in Google Chrome prior to\n107.0.5304.62 allowed a remote attacker who had compromised the renderer\nprocess to leak cross-origin data via a crafted Chrome extension. (Chromium\nsecurity severity: Low)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3661"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3660","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:07.128403+00:00","description":"\nInappropriate implementation in Full screen mode in Google Chrome on\nAndroid prior to 107.0.5304.62 allowed a remote attacker to hide the\ncontents of the Omnibox (URL bar) via a crafted HTML page. (Chromium\nsecurity severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3660"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3659","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:07.128403+00:00","description":"\nUse after free in Accessibility in Google Chrome on Chrome OS prior to\n107.0.5304.62 allowed a remote attacker who convinced a user to engage in\nspecific UI interactions to potentially exploit heap corruption via\nspecific UI interactions. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3659"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3658","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:07.128403+00:00","description":"\nUse after free in Feedback service on Chrome OS in Google Chrome on Chrome\nOS prior to 107.0.5304.62 allowed an attacker who convinced a user to\ninstall a malicious extension to potentially exploit heap corruption via\nspecific UI interaction. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3658"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3657","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:07.128403+00:00","description":"\nUse after free in Extensions in Google Chrome prior to 107.0.5304.62\nallowed an attacker who convinced a user to install a malicious extension\nto potentially exploit heap corruption via a crafted Chrome Extension.\n(Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3657"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3656","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:02.743635+00:00","description":"\nInsufficient data validation in File System in Google Chrome prior to\n107.0.5304.62 allowed a remote attacker to bypass file system restrictions\nvia a crafted HTML page. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3656"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3655","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:02.743635+00:00","description":"\nHeap buffer overflow in Media Galleries in Google Chrome prior to\n107.0.5304.62 allowed an attacker who convinced a user to install a\nmalicious extension to potentially exploit heap corruption via a crafted\nHTML page. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3655"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3654","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:02.743635+00:00","description":"\nUse after free in Layout in Google Chrome prior to 107.0.5304.62 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3654"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3653","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:02.743635+00:00","description":"\nHeap buffer overflow in Vulkan in Google Chrome prior to 107.0.5304.62\nallowed a remote attacker to potentially exploit heap corruption via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3653"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3652","published":"2022-11-01T23:15:00","updated_at":"2025-08-25T23:57:02.743635+00:00","description":"\nType confusion in V8 in Google Chrome prior to 107.0.5304.62 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3652"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":36620,"limit":20,"total_results":79316}