{"cves":[{"id":"CVE-2022-35100","published":"2022-08-16T21:15:00","updated_at":"2025-08-26T12:46:15.994711+00:00","description":"\nSWFTools commit 772e55a2 was discovered to contain a segmentation violation\nvia gfxline_getbbox at /lib/gfxtools.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/182","https://www.cve.org/CVERecord?id=CVE-2022-35100"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-2833","published":"2022-08-16T21:15:00","updated_at":"2025-07-11T07:50:55.209804+00:00","description":"\nEndless Infinite loop in Blender-thumnailing due to logical bugs.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://developer.blender.org/rB24a2b5cb1292f769dd86e314471443976d5e9512","https://developer.blender.org/T99711","https://www.cve.org/CVERecord?id=CVE-2022-2833"],"bugs":[""],"patches":{"blender":["upstream: https://developer.blender.org/rB24a2b5cb1292f769dd86e314471443976d5e9512"],"due":[]},"tags":{},"packages":[{"name":"blender","source":"https://ubuntu.com/security/cve?package=blender","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=blender","debian":"https://tracker.debian.org/pkg/blender","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"due","source":"https://ubuntu.com/security/cve?package=due","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=due","debian":"https://tracker.debian.org/pkg/due","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-2832","published":"2022-08-16T21:15:00","updated_at":"2025-07-11T07:50:55.209804+00:00","description":"\nA flaw was found in Blender 3.3.0. A null pointer dereference exists in\nsource/blender/gpu/opengl/gl_backend.cc that may lead to loss of\nconfidentiality and integrity.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://developer.blender.org/T99706","https://developer.blender.org/D15463","https://developer.blender.org/rB00dc7477022acdd969e4d709a235c0be819efa6c","https://www.cve.org/CVERecord?id=CVE-2022-2832"],"bugs":[""],"patches":{"blender":["upstream: https://developer.blender.org/rB00dc7477022acdd969e4d709a235c0be819efa6c"]},"tags":{},"packages":[{"name":"blender","source":"https://ubuntu.com/security/cve?package=blender","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=blender","debian":"https://tracker.debian.org/pkg/blender","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-2831","published":"2022-08-16T21:15:00","updated_at":"2025-07-11T07:50:50.404260+00:00","description":"\nA flaw was found in Blender 3.3.0. An interger overflow in\nsource/blender/blendthumb/src/blendthumb_extract.cc may lead to program\ncrash or memory corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://developer.blender.org/T99705","https://developer.blender.org/rB32df09b2416a6961704eca0fe73534c8c4e715b2","https://developer.blender.org/rBb1329d7eaa52a11c73b75d19d20bd8f6d11ac535","https://www.cve.org/CVERecord?id=CVE-2022-2831"],"bugs":[""],"patches":{"blender":[]},"tags":{},"packages":[{"name":"blender","source":"https://ubuntu.com/security/cve?package=blender","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=blender","debian":"https://tracker.debian.org/pkg/blender","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-1756","published":"2022-08-16T21:15:00","updated_at":"2025-08-26T12:21:00.423050+00:00","description":"\nIn Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input\nescaping was applied to the PHP unit webrunner admin tool.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=398352","https://www.cve.org/CVERecord?id=CVE-2020-1756"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-1755","published":"2022-08-16T21:15:00","updated_at":"2025-08-26T12:21:00.423050+00:00","description":"\nIn Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers\ncould be used to spoof a user's IP, in order to bypass remote address\nchecks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=398351","https://www.cve.org/CVERecord?id=CVE-2020-1755"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14322","published":"2022-08-16T21:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nIn Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit\nthe amount of files it can load to help mitigate the risk of denial of\nservice.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=407394","https://www.cve.org/CVERecord?id=CVE-2020-14322"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14321","published":"2022-08-16T21:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nIn Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were\nable to assign themselves the manager role within that course.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=407393","https://www.cve.org/CVERecord?id=CVE-2020-14321"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14320","published":"2022-08-16T21:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nIn Moodle before 3.9.1, 3.8.4 and 3.7.7, the filter in the admin task log\nrequired extra sanitizing to prevent a reflected XSS risk.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=407392","https://www.cve.org/CVERecord?id=CVE-2020-14320"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-2817","published":"2022-08-15T23:15:00","updated_at":"2025-08-25T23:52:55.372635+00:00","description":"\nUse After Free in GitHub repository vim/vim prior to 9.0.0213.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"faulty code was added in version 8.2.1183, with commit\n9b7bf9e9, so, versions earlier than that are not affected."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/a7b7d242-3d88-4bde-a681-6c986aff886f","https://github.com/vim/vim/commit/249e1b903a9c0460d618f6dcc59aeb8c03b24b20 (v9.0.0213)","https://github.com/vim/vim/commit/249e1b903a9c0460d618f6dcc59aeb8c03b24b20","https://ubuntu.com/security/notices/USN-6302-1","https://www.cve.org/CVERecord?id=CVE-2022-2817"],"bugs":[""],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/249e1b903a9c0460d618f6dcc59aeb8c03b24b20"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:9.0.0242-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.0213","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-6302-1"],"notices":[{"id":"USN-6302-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-08-21T05:45:06.451790","description":"It was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 22.04 LTS. (CVE-2022-2522, CVE-2022-2580,\nCVE-2022-2817, CVE-2022-2819, CVE-2022-2862, CVE-2022-2889, CVE-2022-2982,\nCVE-2022-3134)\n\nIt was discovered that Vim did not properly perform bounds checks in the\ndiff mode in certain situations. An attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-2598)\n\nIt was discovered that Vim did not properly perform bounds checks in\ncertain situations. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2022-2816)\n\nIt was discovered that Vim incorrectly handled memory when skipping\ncompiled code. An attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2874)\n\nIt was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-3016,\nCVE-2022-3037)\n\nIt was discovered that Vim incorrectly handled memory when invalid line\nnumber on \":for\" is ignored. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2022-3099)\n\nIt was discovered that Vim incorrectly handled memory when passing invalid\narguments to the assert_fails() method. An attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-3153)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm4","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.17","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.11","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm12","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-2580","CVE-2022-2819","CVE-2022-2598","CVE-2022-2862","CVE-2022-3016","CVE-2022-3153","CVE-2022-2889","CVE-2022-2982","CVE-2022-3099","CVE-2022-2816","CVE-2022-2522","CVE-2022-2874","CVE-2022-3134","CVE-2022-3037","CVE-2022-2817"]}]},{"id":"CVE-2022-2816","published":"2022-08-15T22:15:00","updated_at":"2025-08-25T23:52:55.372635+00:00","description":"\nOut-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"the faulty method check_vim9_unlet was added in version\n8.2.0601 with commit d72c1bf0a, so, versions earlier than\nthat are not affected."}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/e2a83037-fcf9-4218-b2b9-b7507dacde58","https://github.com/vim/vim/commit/dbdd16b62560413abcc3c8e893cc3010ccf31666 (v9.0.0212)","https://github.com/vim/vim/commit/dbdd16b62560413abcc3c8e893cc3010ccf31666","https://ubuntu.com/security/notices/USN-6302-1","https://www.cve.org/CVERecord?id=CVE-2022-2816"],"bugs":[""],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/dbdd16b62560413abcc3c8e893cc3010ccf31666"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:9.0.0242-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.11","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.0212","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-6302-1"],"notices":[{"id":"USN-6302-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-08-21T05:45:06.451790","description":"It was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 22.04 LTS. (CVE-2022-2522, CVE-2022-2580,\nCVE-2022-2817, CVE-2022-2819, CVE-2022-2862, CVE-2022-2889, CVE-2022-2982,\nCVE-2022-3134)\n\nIt was discovered that Vim did not properly perform bounds checks in the\ndiff mode in certain situations. An attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-2598)\n\nIt was discovered that Vim did not properly perform bounds checks in\ncertain situations. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2022-2816)\n\nIt was discovered that Vim incorrectly handled memory when skipping\ncompiled code. An attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2874)\n\nIt was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-3016,\nCVE-2022-3037)\n\nIt was discovered that Vim incorrectly handled memory when invalid line\nnumber on \":for\" is ignored. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2022-3099)\n\nIt was discovered that Vim incorrectly handled memory when passing invalid\narguments to the assert_fails() method. An attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-3153)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm4","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.17","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.11","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm12","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-2580","CVE-2022-2819","CVE-2022-2598","CVE-2022-2862","CVE-2022-3016","CVE-2022-3153","CVE-2022-2889","CVE-2022-2982","CVE-2022-3099","CVE-2022-2816","CVE-2022-2522","CVE-2022-2874","CVE-2022-3134","CVE-2022-3037","CVE-2022-2817"]}]},{"id":"CVE-2021-33236","published":"2022-08-15T20:15:00","updated_at":"2025-08-04T19:35:33.026091+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2022-34033. Reason: This candidate is a duplicate of CVE-2022-34033.\nNotes: All CVE users should reference CVE-2022-34033 instead of this\ncandidate.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/michaelrsweet/htmldoc/issues/425","https://github.com/michaelrsweet/htmldoc/commit/a0014be47d614220db111b360fb6170ef6f3937e (v1.9.12)","https://www.cve.org/CVERecord?id=CVE-2021-33236"],"bugs":[""],"patches":{"htmldoc":[]},"tags":{},"packages":[{"name":"htmldoc","source":"https://ubuntu.com/security/cve?package=htmldoc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=htmldoc","debian":"https://tracker.debian.org/pkg/htmldoc","statuses":[{"release_codename":"jammy","status":"not-affected","description":"1.9.15-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.12-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-33235","published":"2022-08-15T20:15:00","updated_at":"2025-08-04T19:35:28.917495+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2022-34035. Reason: This candidate is a duplicate of CVE-2022-34035.\nNotes: All CVE users should reference CVE-2022-34035 instead of this\ncandidate.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/michaelrsweet/htmldoc/issues/426","https://github.com/michaelrsweet/htmldoc/commit/ee778252faebb721afba5a081dd6ad7eaf20eef3 (v1.9.12)","https://www.cve.org/CVERecord?id=CVE-2021-33235"],"bugs":[""],"patches":{"htmldoc":[]},"tags":{},"packages":[{"name":"htmldoc","source":"https://ubuntu.com/security/cve?package=htmldoc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=htmldoc","debian":"https://tracker.debian.org/pkg/htmldoc","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.9.15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.12-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-21365","published":"2022-08-15T20:15:00","updated_at":"2025-08-25T23:23:16.953895+00:00","description":"\nDirectory traversal vulnerability in wkhtmltopdf through 0.12.5 allows\nremote attackers to read local files and disclose sensitive information via\na crafted html file running with the default configurations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/wkhtmltopdf/wkhtmltopdf/commit/2a5f25077895fb075812c0f599326f079a59d6cf (0.12.6)","https://github.com/wkhtmltopdf/wkhtmltopdf/issues/4536","https://ubuntu.com/security/notices/USN-6232-1","https://www.cve.org/CVERecord?id=CVE-2020-21365"],"bugs":[""],"patches":{"wkhtmltopdf":["upstream: https://github.com/wkhtmltopdf/wkhtmltopdf/commit/2a5f25077895fb075812c0f599326f079a59d6cf"]},"tags":{},"packages":[{"name":"wkhtmltopdf","source":"https://ubuntu.com/security/cve?package=wkhtmltopdf","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wkhtmltopdf","debian":"https://tracker.debian.org/pkg/wkhtmltopdf","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"0.12.6-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.9.9-4ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.12.2.4-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"bionic","status":"released","description":"0.12.4-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.12.5-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.12.6-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.12.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.6-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6232-1"],"notices":[{"id":"USN-6232-1","title":"wkhtmltopdf vulnerability","summary":"wkhtmltopdf could be made to expose sensitive information if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-20T19:22:59.970273","description":"It was discovered that wkhtmltopdf was not properly enforcing the\nsame-origin policy when processing certain HTML files. If a user or\nautomated system using wkhtmltopdf were tricked into processing a\nspecially crafted HTML file, an attacker could possibly use this issue to\nexpose sensitive information.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"wkhtmltopdf","version":"0.12.2.4-1ubuntu0.1~esm1","description":"Command line utility to convert html to pdf using WebKit","is_source":true},{"name":"wkhtmltopdf","version":"0.12.2.4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wkhtmltopdf","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"wkhtmltopdf","version":"0.12.5-1ubuntu0.1","description":"Command line utility to convert html to pdf using WebKit","is_source":true},{"name":"wkhtmltopdf","version":"0.12.5-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wkhtmltopdf","version_link":"https://launchpad.net/ubuntu/+source/wkhtmltopdf/0.12.5-1ubuntu0.1","pocket":"security"}],"bionic":[{"name":"wkhtmltopdf","version":"0.12.4-1ubuntu0.1~esm1","description":"Command line utility to convert html to pdf using WebKit","is_source":true},{"name":"wkhtmltopdf","version":"0.12.4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wkhtmltopdf","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"wkhtmltopdf","version":"0.9.9-4ubuntu0.1~esm1","description":"Command line utility to convert html to pdf using WebKit","is_source":true},{"name":"wkhtmltopdf","version":"0.9.9-4ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wkhtmltopdf","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-21365"]}]},{"id":"CVE-2022-35978","published":"2022-08-15T19:15:00","updated_at":"2025-07-11T07:51:48.674821+00:00","description":"\nMinetest is a free open-source voxel game engine with easy modding and game\ncreation. In **single player**, a mod can set a global setting that\ncontrols the Lua script loaded to display the main menu. The script is then\nloaded as soon as the game session is exited. The Lua environment the menu\nruns in is not sandboxed and can directly interfere with the user's system.\nThere are currently no known workarounds.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/minetest/minetest/commit/da71e86633d0b27cd02d7aac9fdac625d141ca13","https://github.com/minetest/minetest/security/advisories/GHSA-663q-pcjw-27cc","https://dev.minetest.net/Changelog#5.5.0_.E2.86.92_5.6.0","https://www.cve.org/CVERecord?id=CVE-2022-35978"],"bugs":[""],"patches":{"minetest":[]},"tags":{},"packages":[{"name":"minetest","source":"https://ubuntu.com/security/cve?package=minetest","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=minetest","debian":"https://tracker.debian.org/pkg/minetest","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-38223","published":"2022-08-15T11:21:00","updated_at":"2025-08-18T17:19:51.500145+00:00","description":"\nThere is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3.\nIt can be triggered by sending a crafted HTML file to the w3m binary. It\nallows an attacker to cause Denial of Service or possibly have unspecified\nother impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-5796-1","https://ubuntu.com/security/notices/USN-5796-2","https://www.cve.org/CVERecord?id=CVE-2022-38223"],"bugs":["https://github.com/tats/w3m/issues/242","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1019599"],"patches":{"w3m":["upstream: https://github.com/tats/w3m/commit/419ca82d57c72242817b55e2eaa4cdbf6916e7fa"]},"tags":{},"packages":[{"name":"w3m","source":"https://ubuntu.com/security/cve?package=w3m","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=w3m","debian":"https://tracker.debian.org/pkg/w3m","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.5.3-15ubuntu0.2+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.5.3-36ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.5.3-37ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.5.3+git20210102-6ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"0.5.3+git20220429-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.5.3+git20220429-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5796-1","USN-5796-2"],"notices":[{"id":"USN-5796-1","title":"w3m vulnerability","summary":"w3m could be made to crash or run programs as your login if it opened a\nmalicious website.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-01-09T13:17:38.741389","description":"It was discovered that w3m incorrectly handled certain HTML files. A remote\nattacker could use this issue to cause w3m to crash, resulting in a denial\nof service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"w3m","version":"0.5.3+git20220429-1ubuntu0.1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m-img","version":"0.5.3+git20220429-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3+git20220429-1ubuntu0.1","pocket":"security"},{"name":"w3m","version":"0.5.3+git20220429-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3+git20220429-1ubuntu0.1","pocket":"security"}],"jammy":[{"name":"w3m","version":"0.5.3+git20210102-6ubuntu0.1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m-img","version":"0.5.3+git20210102-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3+git20210102-6ubuntu0.1","pocket":"security"},{"name":"w3m","version":"0.5.3+git20210102-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3+git20210102-6ubuntu0.1","pocket":"security"}],"focal":[{"name":"w3m","version":"0.5.3-37ubuntu0.1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m-img","version":"0.5.3-37ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-37ubuntu0.1","pocket":"security"},{"name":"w3m","version":"0.5.3-37ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-37ubuntu0.1","pocket":"security"}],"bionic":[{"name":"w3m","version":"0.5.3-36ubuntu0.1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m-img","version":"0.5.3-36ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-36ubuntu0.1","pocket":"security"},{"name":"w3m","version":"0.5.3-36ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":"https://launchpad.net/ubuntu/+source/w3m/0.5.3-36ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-38223"]},{"id":"USN-5796-2","title":"w3m vulnerability","summary":"w3m could be made to crash or run programs as your login if it opened a\nmalicious website.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-01-10T12:17:15.007562","description":"USN-5796-1 fixed a vulnerability in w3m. This update provides\nthe corresponding update for Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that w3m incorrectly handled certain HTML files. A remote\n attacker could use this issue to cause w3m to crash, resulting in a denial\n of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"w3m","version":"0.5.3-15ubuntu0.2+esm1","description":"WWW browsable pager with excellent tables/frames support","is_source":true},{"name":"w3m-img","version":"0.5.3-15ubuntu0.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":null,"pocket":"esm-infra"},{"name":"w3m","version":"0.5.3-15ubuntu0.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/w3m","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-38223"]}]},{"id":"CVE-2022-2819","published":"2022-08-15T11:21:00","updated_at":"2025-08-25T23:52:55.372635+00:00","description":"\nHeap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"faulty code was added in version 8.2.2672, with commit\nb2cb6c8b, so, versions earlier than that are not affected.\nthere is a possibility that version 8.2.2301 (commit\n752fc692) is also affected, but the PoC provided didn't\nreproduce in this version. Anyway, at least versions\nprior to 8.2.2301 are not affected."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/0a9bd71e-66b8-4eb1-9566-7dfd9b097e59","https://github.com/vim/vim/commit/d1d8f6bacb489036d0fd479c9dd3c0102c988889","https://ubuntu.com/security/notices/USN-6302-1","https://www.cve.org/CVERecord?id=CVE-2022-2819"],"bugs":[""],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/d1d8f6bacb489036d0fd479c9dd3c0102c988889"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.11","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.0211","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:9.0.0242-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6302-1"],"notices":[{"id":"USN-6302-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-08-21T05:45:06.451790","description":"It was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 22.04 LTS. (CVE-2022-2522, CVE-2022-2580,\nCVE-2022-2817, CVE-2022-2819, CVE-2022-2862, CVE-2022-2889, CVE-2022-2982,\nCVE-2022-3134)\n\nIt was discovered that Vim did not properly perform bounds checks in the\ndiff mode in certain situations. An attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-2598)\n\nIt was discovered that Vim did not properly perform bounds checks in\ncertain situations. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2022-2816)\n\nIt was discovered that Vim incorrectly handled memory when skipping\ncompiled code. An attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-2874)\n\nIt was discovered that Vim incorrectly handled memory when opening certain\nfiles. If an attacker could trick a user into opening a specially crafted\nfile, it could cause Vim to crash, or possibly execute arbitrary code. This\nissue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-3016,\nCVE-2022-3037)\n\nIt was discovered that Vim incorrectly handled memory when invalid line\nnumber on \":for\" is ignored. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2022-3099)\n\nIt was discovered that Vim incorrectly handled memory when passing invalid\narguments to the assert_fails() method. An attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 22.04\nLTS. (CVE-2022-3153)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm4","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.17","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.1.2269-1ubuntu5.17","pocket":"security"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.11","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.11","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm12","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-2580","CVE-2022-2819","CVE-2022-2598","CVE-2022-2862","CVE-2022-3016","CVE-2022-3153","CVE-2022-2889","CVE-2022-2982","CVE-2022-3099","CVE-2022-2816","CVE-2022-2522","CVE-2022-2874","CVE-2022-3134","CVE-2022-3037","CVE-2022-2817"]}]},{"id":"CVE-2022-35948","published":"2022-08-15T00:00:00","updated_at":"2025-08-25T23:56:47.990037+00:00","description":"\nundici is an HTTP/1.1 client, written from scratch for Node.js.`=<\nundici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when\nusing unsanitized input as request headers, more specifically, inside the\n`content-type` header. Example: ``` import { request } from 'undici' const\nunsanitizedContentTypeInput = 'application/json\\r\\n\\r\\nGET /foo2 HTTP/1.1'\nawait request('http://localhost:3000, { method: 'GET', headers: {\n'content-type': unsanitizedContentTypeInput }, }) ``` The above snippet\nwill perform two requests in a single `request` API call: 1)\n`http://localhost:3000/` 2) `http://localhost:3000/foo2` This issue was\npatched in Undici v5.8.1. Sanitize input when sending content-type headers\nusing user input as a workaround.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/nodejs/undici/security/advisories/GHSA-f772-66g8-q5h3","https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80 (v5.8.2)","https://www.cve.org/CVERecord?id=CVE-2022-35948"],"bugs":[""],"patches":{"node-undici":["upstream: https://github.com/nodejs/undici/commit/66165d604fd0aee70a93ed5c44ad4cc2df395f80"]},"tags":{},"packages":[{"name":"node-undici","source":"https://ubuntu.com/security/cve?package=node-undici","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-undici","debian":"https://tracker.debian.org/pkg/node-undici","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.8.2+dfsg1+~cs18.9.18.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"5.8.2+dfsg1+~cs18.9.18.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-2787","published":"2022-08-15T00:00:00","updated_at":"2025-08-25T23:52:50.552517+00:00","description":"\nSchroot before 1.6.13 had too permissive rules on chroot or session names,\nallowing a denial of service on the schroot service for all users that may\nstart a schroot session.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-5584-1","https://www.cve.org/CVERecord?id=CVE-2022-2787"],"bugs":[""],"patches":{"schroot":["upstream: https://codeberg.org/shelter/reschroot/commit/6f7166a285e1e97aea390be633591f9791b29a6d"]},"tags":{},"packages":[{"name":"schroot","source":"https://ubuntu.com/security/cve?package=schroot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=schroot","debian":"https://tracker.debian.org/pkg/schroot","statuses":[{"release_codename":"bionic","status":"released","description":"1.6.10-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.6.10-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.6.10-12ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.12-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.10-1ubuntu3+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-5584-1"],"notices":[{"id":"USN-5584-1","title":"Schroot vulnerability","summary":"Schroot could be made to denial of service if certain\nschroot names are used.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-08-29T10:12:41.778137","description":"It was discovered that Schroot incorrectly handled certain Schroot names.\nAn attacker could possibly use this issue to break schroot's internal\nstate causing a denial of service.\n","is_hidden":false,"release_packages":{"jammy":[{"name":"schroot","version":"1.6.10-12ubuntu3.1","description":"Execute commands in a chroot environment","is_source":true},{"name":"schroot","version":"1.6.10-12ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":"https://launchpad.net/ubuntu/+source/schroot/1.6.10-12ubuntu3.1","pocket":"security"},{"name":"schroot-common","version":"1.6.10-12ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":"https://launchpad.net/ubuntu/+source/schroot/1.6.10-12ubuntu3.1","pocket":"security"}],"focal":[{"name":"schroot","version":"1.6.10-9ubuntu0.1","description":"Execute commands in a chroot environment","is_source":true},{"name":"schroot","version":"1.6.10-9ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":"https://launchpad.net/ubuntu/+source/schroot/1.6.10-9ubuntu0.1","pocket":"security"},{"name":"schroot-common","version":"1.6.10-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":"https://launchpad.net/ubuntu/+source/schroot/1.6.10-9ubuntu0.1","pocket":"security"}],"bionic":[{"name":"schroot","version":"1.6.10-4ubuntu0.1","description":"Execute commands in a chroot environment","is_source":true},{"name":"schroot","version":"1.6.10-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":"https://launchpad.net/ubuntu/+source/schroot/1.6.10-4ubuntu0.1","pocket":"security"},{"name":"schroot-common","version":"1.6.10-4ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":"https://launchpad.net/ubuntu/+source/schroot/1.6.10-4ubuntu0.1","pocket":"security"}],"xenial":[{"name":"schroot","version":"1.6.10-1ubuntu3+esm1","description":"Execute commands in a chroot environment","is_source":true},{"name":"dchroot-dsa","version":"1.6.10-1ubuntu3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":null,"pocket":"esm-infra"},{"name":"libsbuild-dev","version":"1.6.10-1ubuntu3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":null,"pocket":"esm-infra"},{"name":"dchroot","version":"1.6.10-1ubuntu3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":null,"pocket":"esm-infra"},{"name":"libsbuild-doc","version":"1.6.10-1ubuntu3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":null,"pocket":"esm-infra"},{"name":"schroot","version":"1.6.10-1ubuntu3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":null,"pocket":"esm-infra"},{"name":"schroot-common","version":"1.6.10-1ubuntu3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/schroot","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2022-2787"]}]},{"id":"CVE-2022-2625","published":"2022-08-15T00:00:00","updated_at":"2025-08-18T17:19:03.908560+00:00","description":"\nA vulnerability was found in PostgreSQL. This attack requires permission to\ncreate non-temporary objects in at least one schema, the ability to lure or\nwait for an administrator to create or update an affected extension in that\nschema, and the ability to lure or wait for a victim to use the object\ntargeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three\nprerequisites, this flaw allows an attacker to run arbitrary code as the\nvictim role, which may be a superuser.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."},{"author":"rodrigo-zaiden","note":"PostgreSQL 9.5 is not being maintained by upstream anymore\n(EOL), and without upstream support, there is a potential\nrisk of adding regressions as the fix touches command\npermissions that might need other changes for a specific\nversion. So, for this version, we won't be fixing this CVE."}],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.postgresql.org/support/security/CVE-2022-2625/","https://ubuntu.com/security/notices/USN-5571-1","https://www.cve.org/CVERecord?id=CVE-2022-2625"],"bugs":[""],"patches":{"postgresql-14":["upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=5721da7e41e7a280587bda29cd1674c7da3317f8"],"postgresql-13":["upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=7e92f78abe80e4b30e648a40073abb59057e21f8"],"postgresql-12":["upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=5579726bd60a6e7afb04a3548bced348cd5ffd89"],"postgresql-10":["upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=5919bb5a5989cda232ac3d1f8b9d90f337be2077"],"postgresql-9.5":[],"postgresql-9.3":[],"postgresql-9.1":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.22","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"10.22-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"12.12","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"12.12-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-13","source":"https://ubuntu.com/security/cve?package=postgresql-13","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-13","debian":"https://tracker.debian.org/pkg/postgresql-13","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"13.8","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"14.5-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.5-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"14.5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5571-1"],"notices":[{"id":"USN-5571-1","title":"PostgreSQL vulnerability","summary":"PostgreSQL could be made to run programs when creating or updating\nextensions.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.\n","references":[],"published":"2022-08-18T16:19:58.603616","description":"Sven Klemm discovered that PostgreSQL incorrectly handled extensions. An\nattacker could possibly use this issue to execute arbitrary code when\nextensions are created or updated.\n","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.5-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-server-dev-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-compat3","version":"14.5-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.5-0ubuntu0.22.04.1","pocket":"security"}],"focal":[{"name":"postgresql-12","version":"12.12-0ubuntu0.20.04.1","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-server-dev-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpq-dev","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg6","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpq5","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpgtypes3","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-plperl-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-pltcl-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg-dev","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-plpython3-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-doc-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-client-12","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg-compat3","version":"12.12-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.12-0ubuntu0.20.04.1","pocket":"security"}],"bionic":[{"name":"postgresql-10","version":"10.22-0ubuntu0.18.04.1","description":"Object-relational SQL database","is_source":true},{"name":"postgresql-server-dev-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-pltcl-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg6","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpq-dev","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpgtypes3","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plperl-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg-dev","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plpython3-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpq5","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plpython-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-doc-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-client-10","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg-compat3","version":"10.22-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.22-0ubuntu0.18.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-2625"]}]}],"offset":37660,"limit":20,"total_results":79316}