{"cves":[{"id":"CVE-2022-41343","published":"2022-09-25T00:00:00","updated_at":"2025-08-25T23:58:17.596484+00:00","description":"\nregisterFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file\ninclusion because a URI validation failure does not halt font registration,\nas demonstrated by a @font-face rule.","ubuntu_description":"","notes":[{"author":"ccdm94","note":"the code is not present in version 0.6.2, even though there is a\nregister_font function in include/font_metrics.cls.php which seems\nto contain similar code as the registerFont function being patched\nin the fix commit."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/dompdf/dompdf/releases/tag/v2.0.1","https://github.com/dompdf/dompdf/issues/2994","https://github.com/dompdf/dompdf/pull/2995","https://www.cve.org/CVERecord?id=CVE-2022-41343"],"bugs":[""],"patches":{"php-dompdf":["upstream: https://github.com/dompdf/dompdf/commit/66431c58017d5b1bdb9f6f772b9fbbc5e3d38dc2"]},"tags":{},"packages":[{"name":"php-dompdf","source":"https://ubuntu.com/security/cve?package=php-dompdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-dompdf","debian":"https://tracker.debian.org/pkg/php-dompdf","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3297","published":"2022-09-25T00:00:00","updated_at":"2025-08-25T23:55:07.195125+00:00","description":"\nUse After Free in GitHub repository vim/vim prior to 9.0.0579.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6420-1","https://www.cve.org/CVERecord?id=CVE-2022-3297"],"bugs":["https://huntr.dev/bounties/1aa9ec92-0355-4710-bf85-5bce9effa01c"],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/0ff01835a40f549c5c4a550502f62a2ac9ac447c"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.12","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:9.0.1000-4ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [change too intrusive]","component":null,"pocket":"security"}]}],"notices_ids":["USN-6420-1"],"notices":[{"id":"USN-6420-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-10-09T04:10:20.701256","description":"It was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 22.04 LTS. (CVE-2022-3235, CVE-2022-3278,\nCVE-2022-3297, CVE-2022-3491)\n\nIt was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04\nLTS. (CVE-2022-3352, CVE-2022-4292)\n\nIt was discovered that Vim incorrectly handled memory when replacing in\nvirtualedit mode. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04\nLTS, and Ubuntu 22.04 LTS. (CVE-2022-3234)\n\nIt was discovered that Vim incorrectly handled memory when autocmd changes\nmark. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2022-3256)\n\nIt was discovered that Vim did not properly perform checks on array index\nwith negative width window. An attacker could possibly use this issue to\ncause a denial of service, or execute arbitrary code. (CVE-2022-3324)\n\nIt was discovered that Vim did not properly perform checks on a put command\ncolumn with a visual block. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS, and\nUbuntu 22.04 LTS. (CVE-2022-3520)\n\nIt was discovered that Vim incorrectly handled memory when using autocommand\nto open a window. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2022-3591)\n\nIt was discovered that Vim incorrectly handled memory when updating buffer\nof the component autocmd handler. An attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 20.04 LTS,\nand Ubuntu 22.04 LTS. (CVE-2022-3705)\n\nIt was discovered that Vim incorrectly handled floating point comparison\nwith incorrect operator. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 20.04 LTS. and Ubuntu\n22.04 LTS. (CVE-2022-4293)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm5","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.18","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.12","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm13","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-3591","CVE-2022-3352","CVE-2022-3234","CVE-2022-4293","CVE-2022-3520","CVE-2022-3491","CVE-2022-3256","CVE-2022-3278","CVE-2022-3297","CVE-2022-3705","CVE-2022-4292","CVE-2022-3324","CVE-2022-3235"]}]},{"id":"CVE-2022-3296","published":"2022-09-25T00:00:00","updated_at":"2025-08-25T23:55:07.195125+00:00","description":"\nStack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3296"],"bugs":["https://huntr.dev/bounties/958866b8-526a-4979-9471-39392e0c9077"],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/96b9bf8f74af8abf1e30054f996708db7dc285be"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"change too intrusive","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:9.0.1000-4ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [change too intrusive]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3278","published":"2022-09-23T22:15:00","updated_at":"2025-08-25T23:54:58.019260+00:00","description":"\nNULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6420-1","https://www.cve.org/CVERecord?id=CVE-2022-3278"],"bugs":["https://huntr.dev/bounties/a9fad77e-f245-4ce9-ba15-c7d4c86c4612"],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/69082916c8b5d321545d60b9f5facad0a2dd5a4e"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:9.0.1000-4ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.12","component":null,"pocket":"security"}]}],"notices_ids":["USN-6420-1"],"notices":[{"id":"USN-6420-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-10-09T04:10:20.701256","description":"It was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 22.04 LTS. (CVE-2022-3235, CVE-2022-3278,\nCVE-2022-3297, CVE-2022-3491)\n\nIt was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04\nLTS. (CVE-2022-3352, CVE-2022-4292)\n\nIt was discovered that Vim incorrectly handled memory when replacing in\nvirtualedit mode. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04\nLTS, and Ubuntu 22.04 LTS. (CVE-2022-3234)\n\nIt was discovered that Vim incorrectly handled memory when autocmd changes\nmark. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2022-3256)\n\nIt was discovered that Vim did not properly perform checks on array index\nwith negative width window. An attacker could possibly use this issue to\ncause a denial of service, or execute arbitrary code. (CVE-2022-3324)\n\nIt was discovered that Vim did not properly perform checks on a put command\ncolumn with a visual block. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS, and\nUbuntu 22.04 LTS. (CVE-2022-3520)\n\nIt was discovered that Vim incorrectly handled memory when using autocommand\nto open a window. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2022-3591)\n\nIt was discovered that Vim incorrectly handled memory when updating buffer\nof the component autocmd handler. An attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 20.04 LTS,\nand Ubuntu 22.04 LTS. (CVE-2022-3705)\n\nIt was discovered that Vim incorrectly handled floating point comparison\nwith incorrect operator. An attacker could possibly use this issue to cause\na denial of service. This issue only affected Ubuntu 20.04 LTS. and Ubuntu\n22.04 LTS. (CVE-2022-4293)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm5","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.18","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.18","pocket":"security"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.12","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.12","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm13","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-3591","CVE-2022-3352","CVE-2022-3234","CVE-2022-4293","CVE-2022-3520","CVE-2022-3491","CVE-2022-3256","CVE-2022-3278","CVE-2022-3297","CVE-2022-3705","CVE-2022-4292","CVE-2022-3324","CVE-2022-3235"]}]},{"id":"CVE-2022-22610","published":"2022-09-23T19:15:00","updated_at":"2025-08-25T23:50:28.475220+00:00","description":"\nA memory corruption issue was addressed with improved state management.\nThis issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iOS\n15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content\nmay lead to code execution.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"rodrigo-zaiden","note":"WebKit Bugzilla not public, missing more information."},{"author":"mdeslaur","note":"no indication this affects webkit2gtk so far, marking as\nnot-affected for now"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://support.apple.com/en-us/HT213186","https://support.apple.com/en-us/HT213187","https://support.apple.com/en-us/HT213182","https://support.apple.com/en-us/HT213193","https://support.apple.com/en-us/HT213183","https://www.cve.org/CVERecord?id=CVE-2022-22610"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=232812 (not public)"],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-36944","published":"2022-09-23T18:15:00","updated_at":"2025-07-11T07:51:58.302705+00:00","description":"\nScala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR\nfile. On its own, it cannot be exploited. There is only a risk in\nconjunction with Java object deserialization within an application. In such\nsituations, it allows attackers to erase contents of arbitrary files, make\nnetwork connections, or possibly run arbitrary code (specifically,\nFunction0 functions) via a gadget chain.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.scala-lang.org/download/","https://github.com/scala/scala/pull/10118","https://www.cve.org/CVERecord?id=CVE-2022-36944"],"bugs":[""],"patches":{"scala":["upstream: https://github.com/scala/scala/pull/10118/commits/f24c226211eb340c999d810013efbff35a49863f"]},"tags":{},"packages":[{"name":"scala","source":"https://ubuntu.com/security/cve?package=scala","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=scala","debian":"https://tracker.debian.org/pkg/scala","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13.9","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35099","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a stack overflow via\nImageStream::getPixel(unsigned char*) at /xpdf/Stream.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35099.md","https://github.com/matthiaskramm/swftools/issues/182","https://www.cve.org/CVERecord?id=CVE-2022-35099"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35098","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow\nvia GfxICCBasedColorSpace::getDefaultColor(GfxColor*) at /xpdf/GfxState.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35098.md","https://www.cve.org/CVERecord?id=CVE-2022-35098"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35097","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a segmentation violation\nvia FoFiTrueType::writeTTF at /xpdf/FoFiTrueType.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35097.md","https://www.cve.org/CVERecord?id=CVE-2022-35097"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35096","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow\nvia draw_stroke at /gfxpoly/stroke.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35096.md","https://www.cve.org/CVERecord?id=CVE-2022-35096"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35095","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a segmentation violation\nvia InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35095.md","https://www.cve.org/CVERecord?id=CVE-2022-35095"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35094","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow\nvia DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35094.md","https://www.cve.org/CVERecord?id=CVE-2022-35094"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35093","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a global buffer overflow\nvia DCTStream::transformDataUnit at /xpdf/Stream.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35093.md","https://www.cve.org/CVERecord?id=CVE-2022-35093"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35092","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a segmentation violation\nvia convert_gfxline at /gfxpoly/convert.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35092.md","https://www.cve.org/CVERecord?id=CVE-2022-35092"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35091","published":"2022-09-23T18:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a floating point\nexception (FPE) via DCTStream::readMCURow() at /xpdf/Stream.cc.ow()","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://github.com/Cvjark/Poc/blob/main/swftools/pdf2swf/CVE-2022-35091.md","https://www.cve.org/CVERecord?id=CVE-2022-35091"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-40188","published":"2022-09-23T16:15:00","updated_at":"2025-08-26T12:48:52.043245+00:00","description":"\nKnot Resolver before 5.5.3 allows remote attackers to cause a denial of\nservice (CPU consumption) because of algorithmic complexity. During an\nattack, an authoritative server must return large NS sets or address sets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/CZ-NIC/knot-resolver/commit/f6577a20e493c7fbdac124d7544bf1846b084185 (v5.5.3)","https://www.knot-resolver.cz/2022-09-21-knot-resolver-5.5.3.html","https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1343#note_262558","https://ubuntu.com/security/notices/USN-6225-1","https://www.cve.org/CVERecord?id=CVE-2022-40188"],"bugs":[""],"patches":{"knot-resolver":["upstream: https://github.com/CZ-NIC/knot-resolver/commit/f6577a20e493c7fbdac124d7544bf1846b084185"]},"tags":{},"packages":[{"name":"knot-resolver","source":"https://ubuntu.com/security/cve?package=knot-resolver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=knot-resolver","debian":"https://tracker.debian.org/pkg/knot-resolver","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"5.5.1-5ubuntu0.22.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.1.1-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"3.2.1-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"5.4.4-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1.0.0~beta3-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"5.6.0-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5.6.0-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"5.6.0-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"5.6.0-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"5.6.0-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"5.6.0-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6225-1"],"notices":[{"id":"USN-6225-1","title":"Knot Resolver vulnerability","summary":"Knot Resolver could be made to crash if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-13T02:20:36.356146","description":"It was discovered that Knot Resolver did not correctly handle certain\nclient options. A remote attacker could send requests to malicous domains\nand cause a denial of service. \n","is_hidden":false,"release_packages":{"kinetic":[{"name":"knot-resolver","version":"5.5.1-5ubuntu0.22.10.1","description":"caching, DNSSEC-validating DNS resolver","is_source":true},{"name":"knot-resolver","version":"5.5.1-5ubuntu0.22.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":"https://launchpad.net/ubuntu/+source/knot-resolver/5.5.1-5ubuntu0.22.10.1","pocket":"security"},{"name":"knot-resolver-doc","version":"5.5.1-5ubuntu0.22.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":"https://launchpad.net/ubuntu/+source/knot-resolver/5.5.1-5ubuntu0.22.10.1","pocket":"security"},{"name":"knot-resolver-module-http","version":"5.5.1-5ubuntu0.22.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":"https://launchpad.net/ubuntu/+source/knot-resolver/5.5.1-5ubuntu0.22.10.1","pocket":"security"}],"jammy":[{"name":"knot-resolver","version":"5.4.4-1ubuntu0.1~esm1","description":"caching, DNSSEC-validating DNS resolver","is_source":true},{"name":"knot-resolver","version":"5.4.4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"},{"name":"knot-resolver-doc","version":"5.4.4-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"},{"name":"knot-resolver-module-http","version":"5.4.4-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"knot-resolver","version":"3.2.1-3ubuntu2.1","description":"caching, DNSSEC-validating DNS resolver","is_source":true},{"name":"knot-resolver","version":"3.2.1-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":"https://launchpad.net/ubuntu/+source/knot-resolver/3.2.1-3ubuntu2.1","pocket":"security"},{"name":"knot-resolver-doc","version":"3.2.1-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":"https://launchpad.net/ubuntu/+source/knot-resolver/3.2.1-3ubuntu2.1","pocket":"security"},{"name":"knot-resolver-module-http","version":"3.2.1-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":"https://launchpad.net/ubuntu/+source/knot-resolver/3.2.1-3ubuntu2.1","pocket":"security"}],"bionic":[{"name":"knot-resolver","version":"2.1.1-1ubuntu0.1~esm2","description":"caching, DNSSEC-validating DNS resolver","is_source":true},{"name":"knot-resolver","version":"2.1.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"},{"name":"knot-resolver-doc","version":"2.1.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"},{"name":"libkres6","version":"2.1.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"},{"name":"knot-resolver-module-http","version":"2.1.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"},{"name":"libkres-dev","version":"2.1.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"knot-resolver","version":"1.0.0~beta3-1ubuntu0.1~esm1","description":"caching, DNSSEC-validating DNS resolver","is_source":true},{"name":"knot-resolver","version":"1.0.0~beta3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/knot-resolver","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-40188"]}]},{"id":"CVE-2022-2347","published":"2022-09-23T13:15:00","updated_at":"2025-07-11T07:50:00.229261+00:00","description":"\nThere exists an unchecked length field in UBoot. The U-Boot DFU\nimplementation does not bound the length field in USB DFU download setup\npackets, and it does not verify that the transfer direction corresponds to\nthe specified command. Consequently, if a physical attacker crafts a USB\nDFU download setup packet with a `wLength` greater than 4096 bytes, they\ncan write beyond the heap-allocated request buffer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2022/07/08/2","https://ubuntu.com/security/notices/USN-5764-1","https://ubuntu.com/security/notices/USN-6523-1","https://www.cve.org/CVERecord?id=CVE-2022-2347"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014959"],"patches":{"u-boot":["upstream: https://github.com/u-boot/u-boot/commit/fbce985e28eaca3af82afecc11961aadaf971a7e"],"u-boot-nezha":[]},"tags":{},"packages":[{"name":"u-boot-nezha","source":"https://ubuntu.com/security/cve?package=u-boot-nezha","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=u-boot-nezha","debian":"https://tracker.debian.org/pkg/u-boot-nezha","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2022.04+git20220405.7446a472-0ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"u-boot","source":"https://ubuntu.com/security/cve?package=u-boot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=u-boot","debian":"https://tracker.debian.org/pkg/u-boot","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2022.01+dfsg-2ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"2022.07+dfsg-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2020.10+dfsg-1ubuntu0~18.04.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2021.01+dfsg-3ubuntu0~20.04.5","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2022.07+dfsg-1ubuntu7","component":null,"pocket":"security"}]}],"notices_ids":["USN-5764-1","USN-6523-1"],"notices":[{"id":"USN-5764-1","title":"U-Boot vulnerabilities","summary":"Several security issues were fixed in u-boot.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-12-06T12:54:01.363299","description":"It was discovered that U-Boot incorrectly handled certain USB DFU download\nsetup packets. A local attacker could use this issue to cause U-Boot to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2022-2347)\n\nNicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled\ncertain fragmented IP packets. A local attacker could use this issue to\ncause U-Boot to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu\n20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2022-30552, CVE-2022-30790)\n\nIt was discovered that U-Boot incorrectly handled certain NFS lookup\nreplies. A remote attacker could use this issue to cause U-Boot to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04\nLTS. (CVE-2022-30767)\n\nJincheng Wang discovered that U-Boot incorrectly handled certain SquashFS\nstructures. A local attacker could use this issue to cause U-Boot to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and\nUbuntu 22.04 LTS. (CVE-2022-33103)\n\nTatsuhiko Yasumatsu discovered that U-Boot incorrectly handled certain\nSquashFS structures. A local attacker could use this issue to cause U-Boot\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and\nUbuntu 22.04 LTS. (CVE-2022-33967)\n\nIt was discovered that U-Boot incorrectly handled the i2c command. A local\nattacker could use this issue to cause U-Boot to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-34835)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"u-boot","version":"2022.07+dfsg-1ubuntu4.2","description":"A boot loader for embedded systems","is_source":true},{"name":"u-boot","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-rpi","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-sifive","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-amlogic","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-stm32","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-tools","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-imx","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-tegra","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-microchip","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-sunxi","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-qcom","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-qemu","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-omap","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-mvebu","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-rockchip","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"},{"name":"u-boot-exynos","version":"2022.07+dfsg-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.07+dfsg-1ubuntu4.2","pocket":"security"}],"jammy":[{"name":"u-boot","version":"2022.01+dfsg-2ubuntu2.3","description":"A boot loader for embedded systems","is_source":true},{"name":"u-boot","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-qemu","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-sifive","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-amlogic","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-tools","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-imx","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-tegra","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-microchip","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-sunxi","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-qcom","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-rpi","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-omap","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-mvebu","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-rockchip","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"},{"name":"u-boot-exynos","version":"2022.01+dfsg-2ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2022.01+dfsg-2ubuntu2.3","pocket":"security"}],"bionic":[{"name":"u-boot","version":"2020.10+dfsg-1ubuntu0~18.04.3","description":"A boot loader for embedded systems","is_source":true},{"name":"u-boot","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-qemu","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-amlogic","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-tools","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-imx","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-tegra","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-sunxi","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-qcom","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-rpi","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-omap","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-mvebu","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-rockchip","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"},{"name":"u-boot-exynos","version":"2020.10+dfsg-1ubuntu0~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2020.10+dfsg-1ubuntu0~18.04.3","pocket":"security"}],"focal":[{"name":"u-boot","version":"2021.01+dfsg-3ubuntu0~20.04.5","description":"A boot loader for embedded systems","is_source":true},{"name":"u-boot","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-qemu","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-sifive","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-amlogic","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-tools","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-imx","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-tegra","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-sunxi","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-qcom","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-rpi","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-omap","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-mvebu","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-rockchip","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"},{"name":"u-boot-exynos","version":"2021.01+dfsg-3ubuntu0~20.04.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot","version_link":"https://launchpad.net/ubuntu/+source/u-boot/2021.01+dfsg-3ubuntu0~20.04.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-30767","CVE-2022-30552","CVE-2022-33967","CVE-2022-34835","CVE-2022-30790","CVE-2022-33103","CVE-2022-2347"]},{"id":"USN-6523-1","title":"u-boot-nezha vulnerability","summary":"Several security issues were fixed in u-boot-nezha.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-29T13:41:02.559727","description":"It was discovered that U-Boot incorrectly handled certain USB DFU download\nsetup packets. A local attacker could use this issue to cause U-Boot to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2022-2347)\n\nNicolas Bidron and Nicolas Guigo discovered that U-Boot incorrectly handled\ncertain fragmented IP packets. A local attacker could use this issue to\ncause U-Boot to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2022-30552, CVE-2022-30790)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"u-boot-nezha","version":"2022.04+git20220405.7446a472-0ubuntu0.4","description":"U-Boot for Allwinner Nezha board","is_source":true},{"name":"u-boot-nezha","version":"2022.04+git20220405.7446a472-0ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot-nezha","version_link":"https://launchpad.net/ubuntu/+source/u-boot-nezha/2022.04+git20220405.7446a472-0ubuntu0.4","pocket":"security"}],"lunar":[{"name":"u-boot-nezha","version":"2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2","description":"U-Boot for Allwinner Nezha board","is_source":true},{"name":"u-boot-nezha","version":"2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/u-boot-nezha","version_link":"https://launchpad.net/ubuntu/+source/u-boot-nezha/2022.10-1089-g528ae9bc6c-0ubuntu1.23.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-30790","CVE-2022-2347","CVE-2022-30552"]}]},{"id":"CVE-2022-2566","published":"2022-09-23T12:15:00","updated_at":"2025-08-25T23:52:01.079247+00:00","description":"\nA heap out-of-bounds memory write exists in FFMPEG since version 5.1. The\nsize calculation in `build_open_gop_key_points()` goes through all entries\nin the loop and adds `sc->ctts_data[i].count` to\n`sc->sample_offsets_count`. This can lead to an integer overflow resulting\nin a small allocation with `av_calloc()`. An attacker can cause remote code\nexecution via a malicious mp4 file. We recommend upgrading past commit\nc953baa084607dd1d84c3bfcce3cf6a87c3e6e05","ubuntu_description":"","notes":[{"author":"ccdm94","note":"vulnerability introduced by commit ab77b878f12. Affected version\nis version 5.1, when it includes the code from this commit."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=2126833","https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=6f53f0d09ea4c9c7f7354f018a87ef840315207d (n5.1.1)","https://www.cve.org/CVERecord?id=CVE-2022-2566"],"bugs":[""],"patches":{"ffmpeg":["upstream: https://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=6f53f0d09ea4c9c7f7354f018a87ef840315207d"]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"7:5.1.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7:5.1.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-41322","published":"2022-09-23T00:00:00","updated_at":"2025-08-25T23:58:17.596484+00:00","description":"\nIn Kitty before 0.26.2, insufficient validation in the desktop notification\nescape sequence can lead to arbitrary code execution. The user must display\nattacker-controlled content in the terminal, then click on a notification\npopup.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2","https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes","https://ubuntu.com/security/notices/USN-5659-1","https://www.cve.org/CVERecord?id=CVE-2022-41322"],"bugs":["https://bugs.gentoo.org/868543"],"patches":{"kitty":["upstream: https://github.com/kovidgoyal/kitty/commit/f05783e64d5fa62e1aed603e8d69aced5e49824f"]},"tags":{},"packages":[{"name":"kitty","source":"https://ubuntu.com/security/cve?package=kitty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kitty","debian":"https://tracker.debian.org/pkg/kitty","statuses":[{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.21.2-1ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.26.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.26.5-3ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5659-1"],"notices":[{"id":"USN-5659-1","title":"kitty vulnerabilities","summary":"kitty could be made to run programs if it opened a specially\ncrafted image or desktop notification.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-10-05T23:59:34.051792","description":"Stephane Chauveau discovered that kitty incorrectly handled image\nfilenames with special characters in error messages. A remote\nattacker could possibly use this to execute arbitrary commands.\nThis issue only affected Ubuntu 20.04 LTS. (CVE-2020-35605)\n\nCarter Sande discovered that kitty incorrectly handled escape\nsequences in desktop notifications. A remote attacker could possibly\nuse this to execute arbitrary commands. This issue only affected\nUbuntu 22.04 LTS. (CVE-2022-41322)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"kitty","version":"0.21.2-1ubuntu0.22.04.1","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty-terminfo","version":"0.21.2-1ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.21.2-1ubuntu0.22.04.1","pocket":"security"},{"name":"kitty","version":"0.21.2-1ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.21.2-1ubuntu0.22.04.1","pocket":"security"},{"name":"kitty-doc","version":"0.21.2-1ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.21.2-1ubuntu0.22.04.1","pocket":"security"}],"focal":[{"name":"kitty","version":"0.15.0-1ubuntu0.2","description":"fast, featureful, GPU based terminal emulator","is_source":true},{"name":"kitty-terminfo","version":"0.15.0-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.15.0-1ubuntu0.2","pocket":"security"},{"name":"kitty","version":"0.15.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.15.0-1ubuntu0.2","pocket":"security"},{"name":"kitty-doc","version":"0.15.0-1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/kitty","version_link":"https://launchpad.net/ubuntu/+source/kitty/0.15.0-1ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-41322","CVE-2020-35605"]}]},{"id":"CVE-2022-41318","published":"2022-09-23T00:00:00","updated_at":"2025-08-25T23:58:13.403408+00:00","description":"\nA buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6.\nDue to incorrect integer-overflow protection, the SSPI and SMB\nauthentication helpers are vulnerable to reading unintended memory\nlocations. In some configurations, cleartext credentials from these\nlocations are sent to a client. This is fixed in 5.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2022/09/23/2","https://ubuntu.com/security/notices/USN-5641-1","https://www.cve.org/CVERecord?id=CVE-2022-41318","https://ubuntu.com/security/notices/USN-6857-1"],"bugs":[""],"patches":{"squid":[],"squid3":[]},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.10-1ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"5.2-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"5.6-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"5.6-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"5.6-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"5.6-1ubuntu3","component":null,"pocket":"security"}]},{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"bionic","status":"released","description":"3.5.27-1ubuntu1.14","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.12-1ubuntu7.16+esm3","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-5641-1","USN-6857-1"],"notices":[{"id":"USN-5641-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-09-26T16:23:50.961155","description":"Mikhail Evdokimov discovered that Squid incorrectly handled cache manager\nACLs. A remote attacker could possibly use this issue to obtain sensitive\ninformation. This issue only affected Ubuntu 20.04 LTS, and Ubuntu 22.04\nLTS. (CVE-2022-41317)\n\nIt was discovered that Squid incorrectly handled SSPI and SMB\nauthentication. A remote attacker could use this issue to cause Squid to\ncrash, resulting in a denial of service, or possibly obtain sensitive\ninformation. (CVE-2022-41318)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"squid","version":"5.2-1ubuntu4.2","description":"Web proxy cache server","is_source":true},{"name":"squid-common","version":"5.2-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.2-1ubuntu4.2","pocket":"security"},{"name":"squid-openssl","version":"5.2-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.2-1ubuntu4.2","pocket":"security"},{"name":"squid","version":"5.2-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.2-1ubuntu4.2","pocket":"security"},{"name":"squid-cgi","version":"5.2-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.2-1ubuntu4.2","pocket":"security"},{"name":"squid-purge","version":"5.2-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.2-1ubuntu4.2","pocket":"security"},{"name":"squidclient","version":"5.2-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.2-1ubuntu4.2","pocket":"security"}],"bionic":[{"name":"squid3","version":"3.5.27-1ubuntu1.14","description":"Web proxy cache server","is_source":true},{"name":"squid-common","version":"3.5.27-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.14","pocket":"security"},{"name":"squid","version":"3.5.27-1ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.14","pocket":"security"},{"name":"squid-cgi","version":"3.5.27-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.14","pocket":"security"},{"name":"squid-purge","version":"3.5.27-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.14","pocket":"security"},{"name":"squidclient","version":"3.5.27-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.14","pocket":"security"},{"name":"squid3","version":"3.5.27-1ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.14","pocket":"security"}],"focal":[{"name":"squid","version":"4.10-1ubuntu1.7","description":"Web proxy cache server","is_source":true},{"name":"squid-common","version":"4.10-1ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.7","pocket":"security"},{"name":"squidclient","version":"4.10-1ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.7","pocket":"security"},{"name":"squid","version":"4.10-1ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.7","pocket":"security"},{"name":"squid-cgi","version":"4.10-1ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.7","pocket":"security"},{"name":"squid-purge","version":"4.10-1ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-41317","CVE-2022-41318"]},{"id":"USN-6857-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-06-27T10:48:19.938027","description":"Joshua Rogers discovered that Squid incorrectly handled requests with the\nurn: scheme. A remote attacker could possibly use this issue to cause\nSquid to consume resources, leading to a denial of service. This issue\nonly affected Ubuntu 16.04 LTS. (CVE-2021-28651)\n\nIt was discovered that Squid incorrectly handled SSPI and SMB\nauthentication. A remote attacker could use this issue to cause Squid to\ncrash, resulting in a denial of service, or possibly obtain sensitive\ninformation. This issue only affected Ubuntu 16.04 LTS. (CVE-2022-41318)\n\nJoshua Rogers discovered that Squid incorrectly handled HTTP message\nprocessing. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2023-49285)\n\nJoshua Rogers discovered that Squid incorrectly handled Helper process\nmanagement. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2023-49286)\n\nJoshua Rogers discovered that Squid incorrectly handled HTTP request\nparsing. A remote attacker could possibly use this issue to cause\nSquid to crash, resulting in a denial of service. \n(CVE-2023-50269, CVE-2024-25617)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"squid3","version":"3.5.27-1ubuntu1.14+esm2","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.27-1ubuntu1.14+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid-cgi","version":"3.5.27-1ubuntu1.14+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid-common","version":"3.5.27-1ubuntu1.14+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid-purge","version":"3.5.27-1ubuntu1.14+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid3","version":"3.5.27-1ubuntu1.14+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squidclient","version":"3.5.27-1ubuntu1.14+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"squid3","version":"3.5.12-1ubuntu7.16+esm3","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.12-1ubuntu7.16+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid-cgi","version":"3.5.12-1ubuntu7.16+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid-common","version":"3.5.12-1ubuntu7.16+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid-purge","version":"3.5.12-1ubuntu7.16+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squid3","version":"3.5.12-1ubuntu7.16+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"},{"name":"squidclient","version":"3.5.12-1ubuntu7.16+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2023-49286","CVE-2023-49285","CVE-2024-25617","CVE-2023-50269","CVE-2021-28651","CVE-2022-41318"]}]}],"offset":37140,"limit":20,"total_results":79316}