{"cves":[{"id":"CVE-2022-31056","published":"2022-06-28T18:15:00","updated_at":"2025-08-26T12:45:14.592127+00:00","description":"\nGLPI is a Free Asset and IT Management Software package, Data center\nmanagement, ITIL Service Desk, licenses tracking and software auditing. In\naffected versions all assistance forms (Ticket/Change/Problem) permit sql\ninjection on the actor fields. This issue has been resolved in version\n10.0.2 and all affected users are advised to upgrade.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/glpi-project/glpi/security/advisories/GHSA-9q9x-7xxh-w4cg","https://www.cve.org/CVERecord?id=CVE-2022-31056"],"bugs":[""],"patches":{"glpi":[]},"tags":{},"packages":[{"name":"glpi","source":"https://ubuntu.com/security/cve?package=glpi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glpi","debian":"https://tracker.debian.org/pkg/glpi","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-33108","published":"2022-06-28T17:15:00","updated_at":"2025-07-11T07:51:35.472416+00:00","description":"\nXPDF v4.04 was discovered to contain a stack overflow vulnerability via the\nObject::Copy class of object.cc files.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"xpdf in Debian uses poppler, which is not affected or fixed"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://forum.xpdfreader.com/viewtopic.php?f=3&t=42284","https://forum.xpdfreader.com/viewtopic.php?f=3&t=42286","https://forum.xpdfreader.com/viewtopic.php?f=3&t=42287","https://www.cve.org/CVERecord?id=CVE-2022-33108"],"bugs":[""],"patches":{"xpdf":[],"ipe":[]},"tags":{},"packages":[{"name":"ipe","source":"https://ubuntu.com/security/cve?package=ipe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ipe","debian":"https://tracker.debian.org/pkg/ipe","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xpdf","source":"https://ubuntu.com/security/cve?package=xpdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xpdf","debian":"https://tracker.debian.org/pkg/xpdf","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Debian uses poppler, which is not affected","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-31052","published":"2022-06-28T17:15:00","updated_at":"2025-08-26T12:45:14.592127+00:00","description":"\nSynapse is an open source home server implementation for the Matrix chat\nnetwork. In versions prior to 1.61.1 URL previews of some web pages can\nexhaust the available stack space for the Synapse process due to unbounded\nrecursion. This is sometimes recoverable and leads to an error for the\nrequest causing the problem, but in other cases the Synapse process may\ncrash altogether. It is possible to exploit this maliciously, either by\nmalicious users on the homeserver, or by remote users sending URLs that a\nlocal user's client may automatically request a URL preview for. Remote\nusers are not able to exploit this directly, because the URL preview\nendpoint is authenticated. Deployments with `url_preview_enabled: false`\nset in configuration are not affected. Deployments with\n`url_preview_enabled: true` set in configuration **are** affected.\nDeployments with no configuration value set for `url_preview_enabled` are\nnot affected, because the default is `false`. Administrators of homeservers\nwith URL previews enabled are advised to upgrade to v1.61.1 or higher.\nUsers unable to upgrade should set `url_preview_enabled` to false.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matrix-org/synapse/security/advisories/GHSA-22p3-qrh9-cx32","https://spec.matrix.org/v1.2/client-server-api/#get_matrixmediav3preview_url","https://www.cve.org/CVERecord?id=CVE-2022-31052"],"bugs":[""],"patches":{"matrix-synapse":["upstream: https://github.com/matrix-org/synapse/commit/fa1308061802ac7b7d20e954ba7372c5ac292333"]},"tags":{},"packages":[{"name":"matrix-synapse","source":"https://ubuntu.com/security/cve?package=matrix-synapse","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=matrix-synapse","debian":"https://tracker.debian.org/pkg/matrix-synapse","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"1.61.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.61.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.61.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.61.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.61.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.61.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-0987","published":"2022-06-28T17:15:00","updated_at":"2026-06-06T14:16:26.405158+00:00","description":"\nA flaw was found in PackageKit in the way some of the methods exposed by\nthe Transaction interface examines files. This issue allows a local user to\nmeasure the time the methods take to execute and know whether a file owned\nby root or other users exists.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nThis is a minor security issue"},{"author":"mdeslaur","note":"As of 2026-06-03, there is no fix available for this issue from\npackagekit developers\nThis is just a minor information leak about the existence of a\nroot-owned file or not"}],"codename":null,"priority":"low","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=2064315","https://www.cve.org/CVERecord?id=CVE-2022-0987"],"bugs":[""],"patches":{"packagekit":[]},"tags":{},"packages":[{"name":"packagekit","source":"https://ubuntu.com/security/cve?package=packagekit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=packagekit","debian":"https://tracker.debian.org/pkg/packagekit","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-3779","published":"2022-06-28T17:15:00","updated_at":"2025-08-26T12:33:58.869423+00:00","description":"\nA malicious MySQL server can request local file content from a client using\nruby-mysql prior to version 2.10.0 without explicit authorization from the\nuser. This issue was resolved in version 2.10.0 and later.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.rapid7.com/blog/post/2022/06/28/cve-2021-3779-ruby-mysql-gem-client-file-read-fixed/","https://www.cve.org/CVERecord?id=CVE-2021-3779"],"bugs":[""],"patches":{"ruby-mysql":[]},"tags":{},"packages":[{"name":"ruby-mysql","source":"https://ubuntu.com/security/cve?package=ruby-mysql","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-mysql","debian":"https://tracker.debian.org/pkg/ruby-mysql","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-0085","published":"2022-06-28T15:15:00","updated_at":"2025-08-25T23:46:05.156987+00:00","description":"\nServer-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior\nto 2.0.0.","ubuntu_description":"","notes":[{"author":"ccdm94","note":"the vulnerable code was introduced in version 0.7.0, through commit\n7454ec8f."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/dompdf/dompdf/commit/bb1ef65011a14730b7cfbe73506b4bb8a03704bd","https://huntr.dev/bounties/73dbcc78-5ba9-492f-9133-13bbc9f31236","https://www.cve.org/CVERecord?id=CVE-2022-0085"],"bugs":[""],"patches":{"php-dompdf":["upstream: https://github.com/dompdf/dompdf/commit/bb1ef65011a14730b7cfbe73506b4bb8a03704bd"]},"tags":{},"packages":[{"name":"php-dompdf","source":"https://ubuntu.com/security/cve?package=php-dompdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-dompdf","debian":"https://tracker.debian.org/pkg/php-dompdf","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-41690","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:36.612052+00:00","description":"\nDCMTK through 3.6.6 does not handle memory free properly. The malloced\nmemory for storing all file information are recorded in a global variable\nLST and are not freed properly. Sending specific requests to the dcmqrdb\nprogram can incur a memory leak. An attacker can use it to launch a DoS\nattack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb (DCMTK-3.6.7)","https://github.com/DCMTK/dcmtk","https://ubuntu.com/security/notices/USN-5882-1","https://www.cve.org/CVERecord?id=CVE-2021-41690","https://ubuntu.com/security/notices/USN-7010-1"],"bugs":[""],"patches":{"dcmtk":["upstream: https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb"]},"tags":{},"packages":[{"name":"dcmtk","source":"https://ubuntu.com/security/cve?package=dcmtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dcmtk","debian":"https://tracker.debian.org/pkg/dcmtk","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.6.1~20150924-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"3.6.6-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.6.7-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.6.2-3ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.6.4-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-5882-1","USN-7010-1"],"notices":[{"id":"USN-5882-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-02-22T18:23:35.085020","description":"Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8979)\n\nOmar Ganiev discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS and \nUbuntu 18.04 LTS. (CVE-2019-1010228)\n\nJinsheng Ba discovered that DCMTK incorrectly handled certain requests. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue only affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2021-41687,\nCVE-2021-41688, CVE-2021-41689, and CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\ncertain inputs. If a user or an automated system were tricked into opening\na certain specially crafted input file, a remote attacker could possibly use\nthis issue to execute arbitrary code. This issue only affected \nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2119 and CVE-2022-2120)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.\n(CVE-2022-43272)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk17","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41689","CVE-2022-43272","CVE-2021-41687","CVE-2019-1010228","CVE-2022-2119","CVE-2021-41688","CVE-2015-8979","CVE-2022-2121","CVE-2022-2120","CVE-2021-41690"]},{"id":"USN-7010-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-09-17T05:18:27.111433","description":"Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If\na user or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 20.04 LTS. (CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2022-43272)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\nexecute arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2024-28130)\n\nIt was discovered that DCMTK incorrectly handled memory when processing an\ninvalid incoming DIMSE message. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2024-34508, CVE-2024-34509)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk17t64","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41688","CVE-2024-34508","CVE-2024-34509","CVE-2022-2121","CVE-2021-41689","CVE-2021-41690","CVE-2022-43272","CVE-2024-28130","CVE-2021-41687"]}]},{"id":"CVE-2021-41689","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:36.612052+00:00","description":"\nDCMTK through 3.6.6 does not handle string copy properly. Sending specific\nrequests to the dcmqrdb program, it would query its database and copy the\nresult even if the result is null, which can incur a head-based overflow.\nAn attacker can use it to launch a DoS attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/DCMTK/dcmtk/commit/5c14bf53fb42ceca12bbcc0016e8704b1580920d (DCMTK-3.6.7)","https://github.com/DCMTK/dcmtk","https://github.com/DCMTK/dcmtk/commit/5c14bf53fb42ceca12bbcc0016e8704b1580920d","https://ubuntu.com/security/notices/USN-5882-1","https://www.cve.org/CVERecord?id=CVE-2021-41689","https://ubuntu.com/security/notices/USN-7010-1"],"bugs":[""],"patches":{"dcmtk":[]},"tags":{},"packages":[{"name":"dcmtk","source":"https://ubuntu.com/security/cve?package=dcmtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dcmtk","debian":"https://tracker.debian.org/pkg/dcmtk","statuses":[{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.6.1~20150924-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.6.2-3ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"3.6.6-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.6.4-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-5882-1","USN-7010-1"],"notices":[{"id":"USN-5882-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-02-22T18:23:35.085020","description":"Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8979)\n\nOmar Ganiev discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS and \nUbuntu 18.04 LTS. (CVE-2019-1010228)\n\nJinsheng Ba discovered that DCMTK incorrectly handled certain requests. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue only affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2021-41687,\nCVE-2021-41688, CVE-2021-41689, and CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\ncertain inputs. If a user or an automated system were tricked into opening\na certain specially crafted input file, a remote attacker could possibly use\nthis issue to execute arbitrary code. This issue only affected \nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2119 and CVE-2022-2120)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.\n(CVE-2022-43272)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk17","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41689","CVE-2022-43272","CVE-2021-41687","CVE-2019-1010228","CVE-2022-2119","CVE-2021-41688","CVE-2015-8979","CVE-2022-2121","CVE-2022-2120","CVE-2021-41690"]},{"id":"USN-7010-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-09-17T05:18:27.111433","description":"Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If\na user or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 20.04 LTS. (CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2022-43272)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\nexecute arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2024-28130)\n\nIt was discovered that DCMTK incorrectly handled memory when processing an\ninvalid incoming DIMSE message. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2024-34508, CVE-2024-34509)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk17t64","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41688","CVE-2024-34508","CVE-2024-34509","CVE-2022-2121","CVE-2021-41689","CVE-2021-41690","CVE-2022-43272","CVE-2024-28130","CVE-2021-41687"]}]},{"id":"CVE-2021-41688","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:36.612052+00:00","description":"\nDCMTK through 3.6.6 does not handle memory free properly. The object in the\nprogram is free but its address is still used in other locations. Sending\nspecific requests to the dcmqrdb program will incur a double free. An\nattacker can use it to launch a DoS attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb (DCMTK-3.6.7)","https://github.com/DCMTK/dcmtk","https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb","https://ubuntu.com/security/notices/USN-5882-1","https://www.cve.org/CVERecord?id=CVE-2021-41688","https://ubuntu.com/security/notices/USN-7010-1"],"bugs":[""],"patches":{"dcmtk":[]},"tags":{},"packages":[{"name":"dcmtk","source":"https://ubuntu.com/security/cve?package=dcmtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dcmtk","debian":"https://tracker.debian.org/pkg/dcmtk","statuses":[{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.6.1~20150924-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.6.2-3ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"3.6.6-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.6.4-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-5882-1","USN-7010-1"],"notices":[{"id":"USN-5882-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-02-22T18:23:35.085020","description":"Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8979)\n\nOmar Ganiev discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS and \nUbuntu 18.04 LTS. (CVE-2019-1010228)\n\nJinsheng Ba discovered that DCMTK incorrectly handled certain requests. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue only affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2021-41687,\nCVE-2021-41688, CVE-2021-41689, and CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\ncertain inputs. If a user or an automated system were tricked into opening\na certain specially crafted input file, a remote attacker could possibly use\nthis issue to execute arbitrary code. This issue only affected \nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2119 and CVE-2022-2120)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.\n(CVE-2022-43272)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk17","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41689","CVE-2022-43272","CVE-2021-41687","CVE-2019-1010228","CVE-2022-2119","CVE-2021-41688","CVE-2015-8979","CVE-2022-2121","CVE-2022-2120","CVE-2021-41690"]},{"id":"USN-7010-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-09-17T05:18:27.111433","description":"Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If\na user or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 20.04 LTS. (CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2022-43272)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\nexecute arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2024-28130)\n\nIt was discovered that DCMTK incorrectly handled memory when processing an\ninvalid incoming DIMSE message. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2024-34508, CVE-2024-34509)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk17t64","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41688","CVE-2024-34508","CVE-2024-34509","CVE-2022-2121","CVE-2021-41689","CVE-2021-41690","CVE-2022-43272","CVE-2024-28130","CVE-2021-41687"]}]},{"id":"CVE-2021-41687","published":"2022-06-28T13:15:00","updated_at":"2026-08-31T14:07:29.729165+00:00","description":"\nDCMTK through 3.6.6 does not handle memory free properly. The program\nmalloc a heap memory for parsing data, but does not free it when error in\nparsing. Sending specific requests to the dcmqrdb program incur the memory\nleak. An attacker can use it to launch a DoS attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb (DCMTK-3.6.7)","https://github.com/DCMTK/dcmtk","https://github.com/DCMTK/dcmtk/commit/a9697dfeb672b0b9412c00c7d36d801e27ec85cb","https://ubuntu.com/security/notices/USN-5882-1","https://www.cve.org/CVERecord?id=CVE-2021-41687","https://ubuntu.com/security/notices/USN-7010-1","https://ubuntu.com/security/notices/USN-7010-2"],"bugs":[""],"patches":{"dcmtk":[]},"tags":{},"packages":[{"name":"dcmtk","source":"https://ubuntu.com/security/cve?package=dcmtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dcmtk","debian":"https://tracker.debian.org/pkg/dcmtk","statuses":[{"release_codename":"bionic","status":"released","description":"3.6.2-3ubuntu0.1~esm3","component":null,"pocket":"esm-apps"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.6.6-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.6.1~20150924-5ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.6.4-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-5882-1","USN-7010-1","USN-7010-2"],"notices":[{"id":"USN-5882-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-02-22T18:23:35.085020","description":"Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8979)\n\nOmar Ganiev discovered that DCMTK incorrectly handled buffers. If a user or\nan automated system were tricked into opening a certain specially crafted \ninput file, a remote attacker could possibly use this issue to cause a \ndenial of service. This issue only affected Ubuntu 16.04 LTS and \nUbuntu 18.04 LTS. (CVE-2019-1010228)\n\nJinsheng Ba discovered that DCMTK incorrectly handled certain requests. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue only affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2021-41687,\nCVE-2021-41688, CVE-2021-41689, and CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\ncertain inputs. If a user or an automated system were tricked into opening\na certain specially crafted input file, a remote attacker could possibly use\nthis issue to execute arbitrary code. This issue only affected \nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2119 and CVE-2022-2120)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to \ncause a denial of service. This issue affected Ubuntu 16.04 LTS, \nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10.\n(CVE-2022-43272)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk17","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"dcmtk","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.7-6ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.7-6ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41689","CVE-2022-43272","CVE-2021-41687","CVE-2019-1010228","CVE-2022-2119","CVE-2021-41688","CVE-2015-8979","CVE-2022-2121","CVE-2022-2120","CVE-2021-41690"]},{"id":"USN-7010-1","title":"DCMTK vulnerabilities","summary":"Several security issues were fixed in DCMTK.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-09-17T05:18:27.111433","description":"Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If\na user or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690)\n\nSharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\npointers. If a user or an automated system were tricked into opening a\ncertain specially crafted input file, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected\nUbuntu 20.04 LTS. (CVE-2022-2121)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2022-43272)\n\nIt was discovered that DCMTK incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a certain specially\ncrafted input file, a remote attacker could possibly use this issue to\nexecute arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2024-28130)\n\nIt was discovered that DCMTK incorrectly handled memory when processing an\ninvalid incoming DIMSE message. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2024-34508, CVE-2024-34509)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.1","pocket":"security"}],"jammy":[{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk16","version":"3.6.6-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk17t64","version":"3.6.7-9.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41688","CVE-2024-34508","CVE-2024-34509","CVE-2022-2121","CVE-2021-41689","CVE-2021-41690","CVE-2022-43272","CVE-2024-28130","CVE-2021-41687"]},{"id":"USN-7010-2","title":"DCMTK regression","summary":"USN-7010-1 introduced a regression in DCMTK","instructions":"In general, a standard system update will make all the necessary changes.\n\n\n","references":[],"published":"2025-07-08T05:47:38.260163","description":"USN-7010-1 fixed vulnerabilities in DCMTK. The update introduced a\nregression. This update fixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If\n a user or an automated system were tricked into opening a certain specially\n crafted input file, a remote attacker could possibly use this issue to\n cause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n (CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690)\n\n Sharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled\n pointers. If a user or an automated system were tricked into opening a\n certain specially crafted input file, a remote attacker could possibly use\n this issue to cause a denial of service. This issue only affected\n Ubuntu 20.04 LTS. (CVE-2022-2121)\n\n It was discovered that DCMTK incorrectly handled certain inputs. If a\n user or an automated system were tricked into opening a certain specially\n crafted input file, a remote attacker could possibly use this issue to\n cause a denial of service. This issue only affected Ubuntu 20.04 LTS.\n (CVE-2022-43272)\n\n It was discovered that DCMTK incorrectly handled certain inputs. If a\n user or an automated system were tricked into opening a certain specially\n crafted input file, a remote attacker could possibly use this issue to\n execute arbitrary code. This issue was only addressed in Ubuntu 20.04 LTS\n and Ubuntu 22.04 LTS. (CVE-2024-28130)\n\n It was discovered that DCMTK incorrectly handled memory when processing an\n invalid incoming DIMSE message. An attacker could possibly use this issue\n to cause a denial of service. (CVE-2024-34508, CVE-2024-34509)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm3","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.2-3ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.2-3ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.2-3ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk12","version":"3.6.2-3ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.2","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.4-2.1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.2","pocket":"security"},{"name":"dcmtk-doc","version":"3.6.4-2.1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.2","pocket":"security"},{"name":"libdcmtk-dev","version":"3.6.4-2.1ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.2","pocket":"security"},{"name":"libdcmtk14","version":"3.6.4-2.1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":"https://launchpad.net/ubuntu/+source/dcmtk/3.6.4-2.1ubuntu0.2","pocket":"security"}],"xenial":[{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm3","description":"OFFIS DICOM toolkit command line utilities","is_source":true},{"name":"dcmtk","version":"3.6.1~20150924-5ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"dcmtk-doc","version":"3.6.1~20150924-5ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk-dev","version":"3.6.1~20150924-5ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"},{"name":"libdcmtk5","version":"3.6.1~20150924-5ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dcmtk","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41687"]}]},{"id":"CVE-2021-40944","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:20.005659+00:00","description":"\nIn GPAC MP4Box 1.1.0, there is a Null pointer reference in the function\ngf_filter_pid_get_packet function in src/filter_core/filter_pid.c:5394, as\ndemonstrated by GPAC. This can cause a denial of service (DOS).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1906","https://github.com/gpac/gpac/commit/44fdc3d972c31c56efe73e1a3b63438d46087652 (v2.0.0)","https://www.cve.org/CVERecord?id=CVE-2021-40944"],"bugs":[""],"patches":{"gpac":["upstream: https://github.com/gpac/gpac/commit/44fdc3d972c31c56efe73e1a3b63438d46087652"]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0, 2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40943","published":"2022-06-28T13:15:00","updated_at":"2025-07-11T07:48:14.717044+00:00","description":"\nIn Bento4 1.6.0-638, there is a null pointer reference in the function\nAP4_DescriptorListInspector::Action function in Ap4Descriptor.h:124 , as\ndemonstrated by GPAC. This can cause a denial of service (DOS).","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-40943"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40609","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:04.126447+00:00","description":"\nThe GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial\nof service via a crafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1894","https://github.com/gpac/gpac/commit/86c1566f040b2b84c72afcb6cbd444c5aff56cfe (v2.0.0)","https://www.cve.org/CVERecord?id=CVE-2021-40609"],"bugs":[""],"patches":{"gpac":["upstream: https://github.com/gpac/gpac/commit/86c1566f040b2b84c72afcb6cbd444c5aff56cfe"]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0, 2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40608","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:04.126447+00:00","description":"\nThe gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to\ncause a denial of service via a crafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1883","https://github.com/gpac/gpac/commit/b09c75dc2d4bf68ac447daa71e72365aa30231a9 (v2.0.0)","https://www.cve.org/CVERecord?id=CVE-2021-40608"],"bugs":[""],"patches":{"gpac":["upstream: https://github.com/gpac/gpac/commit/b09c75dc2d4bf68ac447daa71e72365aa30231a9"]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0, 2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40607","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:04.126447+00:00","description":"\nThe schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial\nof service via a crafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1879","https://github.com/gpac/gpac/commit/f19668964bf422cf5a63e4dbe1d3c6c75edadcbb (v2.0.0)","https://www.cve.org/CVERecord?id=CVE-2021-40607"],"bugs":[""],"patches":{"gpac":["upstream: https://github.com/gpac/gpac/commit/f19668964bf422cf5a63e4dbe1d3c6c75edadcbb"]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0, 2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40606","published":"2022-06-28T13:15:00","updated_at":"2025-08-26T12:35:04.126447+00:00","description":"\nThe gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a\ndenial of service via a crafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1885","https://github.com/gpac/gpac/commit/f5a038e6893019ee471b6a57490cf7a495673816 (v2.0.0)","https://www.cve.org/CVERecord?id=CVE-2021-40606"],"bugs":[""],"patches":{"gpac":["upstream: https://github.com/gpac/gpac/commit/f5a038e6893019ee471b6a57490cf7a495673816"]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.0, 2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.0+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-33879","published":"2022-06-27T22:15:00","updated_at":"2025-07-11T07:51:39.452662+00:00","description":"\nThe initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the\nStandardsExtractingContentHandler were insufficient, and we found a\nseparate, new regex DoS in a different regex in the\nStandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2022/06/27/5","https://www.cve.org/CVERecord?id=CVE-2022-33879","https://ubuntu.com/security/notices/USN-7529-1"],"bugs":[""],"patches":{"tika":[]},"tags":{},"packages":[{"name":"tika","source":"https://ubuntu.com/security/cve?package=tika","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tika","debian":"https://tracker.debian.org/pkg/tika","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28.4, 2.4.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.22-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.22-2ubuntu0.22.04.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-7529-1"],"notices":[{"id":"USN-7529-1","title":"Apache Tika vulnerabilities","summary":"Several security issues were fixed in Apache Tika.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-05-23T13:52:50.718304","description":"It was discovered that Apache Tika can have an excessive memory usage by\nusing a crafted or corrupt PSD file. An attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu\n20.04 LTS. (CVE-2020-1950, CVE-2020-1951)\n\nIt was discovered that Apache Tika incorrectly handled certain regular\nexpressions. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-30126, CVE-2022-30973, CVE-2022-33879)","is_hidden":false,"release_packages":{"focal":[{"name":"tika","version":"1.22-1ubuntu0.1~esm1","description":"A content analysis toolkit","is_source":true},{"name":"libtika-java","version":"1.22-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tika","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"tika","version":"1.22-2ubuntu0.22.04.1~esm1","description":"A content analysis toolkit","is_source":true},{"name":"libtika-java","version":"1.22-2ubuntu0.22.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tika","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-30126","CVE-2020-1951","CVE-2022-30973","CVE-2022-33879","CVE-2020-1950"]}]},{"id":"CVE-2022-31091","published":"2022-06-27T22:15:00","updated_at":"2025-07-11T07:51:18.570714+00:00","description":"\nGuzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers\non requests are sensitive information. In affected versions on making a\nrequest which responds with a redirect to a URI with a different port, if\nwe choose to follow it, we should remove the `Authorization` and `Cookie`\nheaders from the request, before containing. Previously, we would only\nconsider a change in host or scheme. Affected Guzzle 7 users should upgrade\nto Guzzle 7.4.5 as soon as possible. Affected users using any earlier\nseries of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a\npartial fix was implemented in Guzzle 7.4.2, where a change in host would\ntrigger removal of the curl-added Authorization header, however this\nearlier fix did not cover change in scheme or change in port. An\nalternative approach would be to use your own redirect middleware, rather\nthan ours, if you are unable to upgrade. If you do not require or expect\nredirects to be followed, one should simply disable redirects all together.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699","https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82 (7.4.5)","https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82","https://www.cve.org/CVERecord?id=CVE-2022-31091"],"bugs":[""],"patches":{"guzzle":["upstream: https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82"],"mediawiki":[],"civicrm":[],"icinga-php-thirdparty":[],"icingaweb2-module-reactbundle":[]},"tags":{},"packages":[{"name":"civicrm","source":"https://ubuntu.com/security/cve?package=civicrm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=civicrm","debian":"https://tracker.debian.org/pkg/civicrm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"icinga-php-thirdparty","source":"https://ubuntu.com/security/cve?package=icinga-php-thirdparty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icinga-php-thirdparty","debian":"https://tracker.debian.org/pkg/icinga-php-thirdparty","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"icingaweb2-module-reactbundle","source":"https://ubuntu.com/security/cve?package=icingaweb2-module-reactbundle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icingaweb2-module-reactbundle","debian":"https://tracker.debian.org/pkg/icingaweb2-module-reactbundle","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"guzzle","source":"https://ubuntu.com/security/cve?package=guzzle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=guzzle","debian":"https://tracker.debian.org/pkg/guzzle","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"}]},{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-31090","published":"2022-06-27T22:15:00","updated_at":"2025-07-11T07:51:18.570714+00:00","description":"\nGuzzle, an extensible PHP HTTP client. `Authorization` headers on requests\nare sensitive information. In affected versions when using our Curl\nhandler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an\n`Authorization` header. On making a request which responds with a redirect\nto a URI with a different origin (change in host, scheme or port), if we\nchoose to follow it, we should remove the `CURLOPT_HTTPAUTH` option before\ncontinuing, stopping curl from appending the `Authorization` header to the\nnew request. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon\nas possible. Affected users using any earlier series of Guzzle should\nupgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented\nin Guzzle 7.4.2, where a change in host would trigger removal of the\ncurl-added Authorization header, however this earlier fix did not cover\nchange in scheme or change in port. If you do not require or expect\nredirects to be followed, one should simply disable redirects all together.\nAlternatively, one can specify to use the Guzzle steam handler backend,\nrather than curl.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r","https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82 (7.4.5)","https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82","https://www.cve.org/CVERecord?id=CVE-2022-31090"],"bugs":[""],"patches":{"guzzle":["upstream: https://github.com/guzzle/guzzle/commit/1dd98b0564cb3f6bd16ce683cb755f94c10fbd82"],"mediawiki":[],"civicrm":[],"icingaweb2-module-reactbundle":[],"icinga-php-thirdparty":[]},"tags":{},"packages":[{"name":"civicrm","source":"https://ubuntu.com/security/cve?package=civicrm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=civicrm","debian":"https://tracker.debian.org/pkg/civicrm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"icingaweb2-module-reactbundle","source":"https://ubuntu.com/security/cve?package=icingaweb2-module-reactbundle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icingaweb2-module-reactbundle","debian":"https://tracker.debian.org/pkg/icingaweb2-module-reactbundle","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"icinga-php-thirdparty","source":"https://ubuntu.com/security/cve?package=icinga-php-thirdparty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icinga-php-thirdparty","debian":"https://tracker.debian.org/pkg/icinga-php-thirdparty","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"guzzle","source":"https://ubuntu.com/security/cve?package=guzzle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=guzzle","debian":"https://tracker.debian.org/pkg/guzzle","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"7.4.5-1","component":null,"pocket":"security"}]},{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.35.7-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-31088","published":"2022-06-27T21:15:00","updated_at":"2025-07-16T12:33:08.459624+00:00","description":"\nLDAP Account Manager (LAM) is a webfrontend for managing entries (e.g.\nusers, groups, DHCP settings) stored in an LDAP directory. In versions\nprior to 8.0 the user name field at login could be used to enumerate LDAP\ndata. This is only the case for LDAP search configuration. This issue has\nbeen fixed in version 8.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/LDAPAccountManager/lam/security/advisories/GHSA-wxf8-9x99-6gp4","https://github.com/LDAPAccountManager/lam/commit/f1d5d04952f39a1b4ea203d3964fa88e1429dfd4","https://www.cve.org/CVERecord?id=CVE-2022-31088"],"bugs":[""],"patches":{"ldap-account-manager":[]},"tags":{},"packages":[{"name":"ldap-account-manager","source":"https://ubuntu.com/security/cve?package=ldap-account-manager","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ldap-account-manager","debian":"https://tracker.debian.org/pkg/ldap-account-manager","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8.0.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0, 8.0.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8.0.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"8.0.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"8.0.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"8.0.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":38220,"limit":20,"total_results":79316}