{"cves":[{"id":"CVE-2022-35475","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6e41a8.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35475"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35474","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6b544e.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35474"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35473","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a segmentation violation via\n/release-x64/otfccdump+0x4fe9a7.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35473"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35472","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a global overflow via\n/release-x64/otfccdump+0x718693.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35472"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35471","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6e41b0.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35471"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35470","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x65fc97.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35470"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35469","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:34.726798+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a segmentation violation via\n/x86_64-linux-gnu/libc.so.6+0xbb384.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35469"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35468","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6e420d.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35468"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35467","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6e41b8.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35467"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35466","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6c0473.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35466"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35465","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6c0414.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35465"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35464","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6171b2.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35464"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35463","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6b0478.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35463"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35462","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6c0bc3.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35462"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35461","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6c0a32.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35461"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35460","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x61731f.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35460"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35459","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:30.031866+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6e412a.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35459"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35458","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:25.518242+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6b05ce.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35458"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35456","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:25.518242+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x617087.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35456"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-35455","published":"2022-08-16T21:15:00","updated_at":"2025-08-25T23:56:25.518242+00:00","description":"\nOTFCC v0.10.4 was discovered to contain a heap-buffer overflow via\n/release-x64/otfccdump+0x6b0d63.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"From Debian:\nThe otfccdump binary is not build by any source package,\nhence we are not affected. Yes, we carry the source code of\nthe program, but we don't use it."}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cvjark.github.io/2022/07/06/CVE-2022-33047/","https://www.cve.org/CVERecord?id=CVE-2022-35455"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":37620,"limit":20,"total_results":79316}