{"cves":[{"id":"CVE-2021-45292","published":"2021-12-21T18:15:00","updated_at":"2025-08-26T12:36:58.917433+00:00","description":"\nThe gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause\na denial of service (Invalid memory address dereference) via a crafted file\nin the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1958","https://github.com/gpac/gpac/commit/3dafcb5e71e9ffebb50238784dcad8b105da81f6","https://www.cve.org/CVERecord?id=CVE-2021-45292"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45291","published":"2021-12-21T18:15:00","updated_at":"2025-08-26T12:36:58.917433+00:00","description":"\nThe gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a\ndenial of service (Invalid memory address dereference) via a crafted file\nin the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1955","https://github.com/gpac/gpac/commit/a07c64979af592aad56bc175157b7397e43fa9cc","https://www.cve.org/CVERecord?id=CVE-2021-45291"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45290","published":"2021-12-21T18:15:00","updated_at":"2025-08-26T12:36:58.917433+00:00","description":"\nA Denial of Service vulnerability exits in Binaryen 103 due to an assertion\nabort in wasm::handle_unreachable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/4383","https://github.com/WebAssembly/binaryen/pull/4389","https://github.com/WebAssembly/binaryen/commit/62d83d5fcad015ce52f0f3122eab9df1c629cafb (version_104)","https://www.cve.org/CVERecord?id=CVE-2021-45290"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"104-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"108-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"108-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"108-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"108-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"108-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"108-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"108-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45289","published":"2021-12-21T18:15:00","updated_at":"2025-08-26T12:36:58.917433+00:00","description":"\nA vulnerability exists in GPAC 1.0.1 due to an omission of\nsecurity-relevant Information, which could cause a Denial of Service. The\nprogram terminates with signal SIGKILL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1972","https://github.com/gpac/gpac/commit/5e1f084e0c6ad2736c9913715c4abb57c554209d","https://www.cve.org/CVERecord?id=CVE-2021-45289"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45288","published":"2021-12-21T17:15:00","updated_at":"2025-08-04T18:13:42.394851+00:00","description":"\nA Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could\ncause a Denail of Service via a crafted file in the MP4Box command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1956","https://github.com/gpac/gpac/commit/9bbce9634cba1128aa4b96d590be578ae3ce80b3","https://www.cve.org/CVERecord?id=CVE-2021-45288"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45451","published":"2021-12-21T07:15:00","updated_at":"2025-07-11T07:48:44.723762+00:00","description":"\nIn Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or\noracle-based decryption when the output buffer is at memory locations\naccessible to an untrusted application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/ARMmbed/mbedtls/releases/tag/v3.1.0","https://www.cve.org/CVERecord?id=CVE-2021-45451"],"bugs":[""],"patches":{"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.6.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45450","published":"2021-12-21T07:15:00","updated_at":"2025-10-10T18:51:10.176811+00:00","description":"\nIn Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and\npsa_cipher_encrypt allow policy bypass or oracle-based decryption when the\noutput buffer is at memory locations accessible to an untrusted\napplication.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/ARMmbed/mbedtls/releases/tag/v3.1.0","https://github.com/ARMmbed/mbedtls/releases/tag/v2.28.0","https://www.cve.org/CVERecord?id=CVE-2021-45450"],"bugs":[""],"patches":{"mbedtls":["upstream: https://github.com/Mbed-TLS/mbedtls/commit/c423acbe0f7957d8ef1e6036c2429c9f79c6f05e","upstream: https://github.com/Mbed-TLS/mbedtls/commit/4c224fe3ccbe527a2b7d55a927f1f09511ff1b83"]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.28.0-1build1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.28.0-1build1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.28.0-1build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.28.0-1build1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.28.0-1build1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.28.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-44858","published":"2021-12-20T09:15:00","updated_at":"2025-08-26T12:36:43.918354+00:00","description":"\nAn issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3,\nand 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed\nby action=mcrundo and action=mcrrestore to view private pages on a private\nwiki that has at least one page set in $wgWhitelistRead.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T297322","https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/QEN3EK4JXAVJMJ5GF3GYOAKNJPEKFQYA/","https://www.cve.org/CVERecord?id=CVE-2021-44858"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/mediawiki/+bug/1955352"],"patches":{"mediawiki":["upstream: https://github.com/wikimedia/mediawiki/commit/7b0c94fb0be44be33393e34cf8bc73798105f78e","upstream: https://github.com/wikimedia/mediawiki/commit/5d5a3c0720520f75e723d3b5a37e793a6e674e4f"]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:1.35.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-44732","published":"2021-12-20T08:15:00","updated_at":"2026-03-25T21:02:21.176707+00:00","description":"\nMbed TLS before 3.0.1 has a double free in certain out-of-memory\nconditions, as demonstrated by an mbedtls_ssl_set_session() failure.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2021-12","https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.12","https://github.com/ARMmbed/mbedtls/releases","https://github.com/ARMmbed/mbedtls/releases/tag/v3.1.0","https://bugs.gentoo.org/829660","https://github.com/ARMmbed/mbedtls/releases/tag/v2.28.0","https://www.cve.org/CVERecord?id=CVE-2021-44732","https://ubuntu.com/security/notices/USN-8123-1"],"bugs":[""],"patches":{"mbedtls":["upstream: https://github.com/Mbed-TLS/mbedtls/commit/eb490aabf6a9f47c074ec476d0d4997c2362cdbc"]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.8.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.6.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.6.2-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.16.4-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.6.2-3ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8123-1"],"notices":[{"id":"USN-8123-1","title":"Mbed TLS vulnerabilities","summary":"Several security issues were fixed in mbedtls.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-25T16:22:11.870086","description":"It was discovered that Mbed TLS incorrectly handled memory allocation\nfailures. A remote attacker could possibly use this issue to crash\nthe program. This issue only affected Ubuntu 18.04 LTS and Ubuntu\n20.04 LTS. (CVE-2021-44732)\n\nJonathan Winzig discovered that Mbed TLS incorrectly handled crafted\ninputs. A remote attacker could possibly use this issue to crash the\nprogram, resulting in a denial of service. This issue only affected\nUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS. (CVE-2024-23775)\n\nIt was discovered that Mbed TLS incorrectly handled the TLS\nhandshake. A remote attacker could possibly use this issue to\nbreak the security guarantees of the TLS handshake.\n(CVE-2025-27810)\n\nLinh Le and Ngan Nguyen discovered that Mbed TLS incorrectly\ndocumented the behavior of a function. Application code relying\non the documented behavior might be affected. A remote attacker\ncould possibly use this issue to execute arbitrary code.\n(CVE-2025-47917)\n\nLinh Le and Ngan Nguyen discovered that Mbed TLS incorrectly handled\ncrafted input. A remote attacker could possibly use this issue to\ncrash the program, resulting in a denial of service. (CVE-2025-48965)\n\nIt was discovered that Mbed TLS incorrectly handled a race condition.\nAn attacker could possibly use this issue to extract AES keys.\n(CVE-2025-52496)\n\nLinh Le and Ngan Nguyen discovered that Mbed TLS incorrectly handled\ncertain invalid input. A remote attacker could possibly use this\nissue to crash the program, resulting in a denial of service.\n(CVE-2025-52497)","is_hidden":false,"release_packages":{"bionic":[{"name":"mbedtls","version":"2.8.0-1ubuntu0.1~esm1","description":"Lightweight crypto and SSL/TLS library","is_source":true},{"name":"libmbedcrypto1","version":"2.8.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-dev","version":"2.8.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-doc","version":"2.8.0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls10","version":"2.8.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedx509-0","version":"2.8.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"mbedtls","version":"2.16.4-1ubuntu2+esm1","description":"Lightweight crypto and SSL/TLS library","is_source":true},{"name":"libmbedcrypto3","version":"2.16.4-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-dev","version":"2.16.4-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-doc","version":"2.16.4-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls12","version":"2.16.4-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedx509-0","version":"2.16.4-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"mbedtls","version":"2.28.0-1ubuntu0.1~esm1","description":"Lightweight crypto and SSL/TLS library","is_source":true},{"name":"libmbedcrypto7","version":"2.28.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-dev","version":"2.28.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-doc","version":"2.28.0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls14","version":"2.28.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedx509-1","version":"2.28.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"mbedtls","version":"2.28.8-1ubuntu0.1~esm1","description":"Lightweight crypto and SSL/TLS library","is_source":true},{"name":"libmbedcrypto7t64","version":"2.28.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-dev","version":"2.28.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls-doc","version":"2.28.8-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedtls14t64","version":"2.28.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"},{"name":"libmbedx509-1t64","version":"2.28.8-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mbedtls","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2025-27810","CVE-2021-44732","CVE-2024-23775","CVE-2025-47917","CVE-2025-48965","CVE-2025-52496","CVE-2025-52497"]}]},{"id":"CVE-2021-44790","published":"2021-12-20T00:00:00","updated_at":"2025-08-25T23:43:06.406286+00:00","description":"\nA carefully crafted request body can cause a buffer overflow in the mod_lua\nmultipart parser (r:parsebody() called from Lua scripts). The Apache httpd\nteam is not aware of an exploit for the vulnerabilty though it might be\npossible to craft one. This issue affects Apache HTTP Server 2.4.51 and\nearlier.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Fixed by r1896039 in 2.4.x"},{"author":"sbeattie","note":"mod_lua is not runtime enabled with Apache's package config\nin Ubuntu by default."}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://httpd.apache.org/security/vulnerabilities_24.html","https://ubuntu.com/security/notices/USN-5212-1","https://ubuntu.com/security/notices/USN-5212-2","https://www.cve.org/CVERecord?id=CVE-2021-44790"],"bugs":[""],"patches":{"apache2":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1896039","upstream: https://github.com/apache/httpd/commit/07b9768cef6a224d256358c404c6ed5622d8acce"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.21","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.52","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"2.4.46-4ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2.4.48-3.1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm4","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-5212-1","USN-5212-2"],"notices":[{"id":"USN-5212-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-01-06T14:48:19.125348","description":"It was discovered that the Apache HTTP Server incorrectly handled certain\nforward proxy requests. A remote attacker could use this issue to cause\nthe server to crash, resulting in a denial of service, or possibly perform\na Server Side Request Forgery attack. (CVE-2021-44224)\n\nIt was discovered that the Apache HTTP Server Lua module incorrectly\nhandled memory in the multipart parser. A remote attacker could use this\nissue to cause the server to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2021-44790)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"apache2","version":"2.4.46-4ubuntu1.5","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-utils","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-dev","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-doc","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-bin","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"}],"impish":[{"name":"apache2","version":"2.4.48-3.1ubuntu3.2","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-utils","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-dev","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-doc","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-bin","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"}],"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.21","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.9","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-44790","CVE-2021-44224"]},{"id":"USN-5212-2","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-01-10T11:14:47.876943","description":"USN-5212-1 fixed several vulnerabilities in Apache. This update provides\nthe corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that the Apache HTTP Server incorrectly handled certain\n forward proxy requests. A remote attacker could use this issue to cause\n the server to crash, resulting in a denial of service, or possibly perform\n a Server Side Request Forgery attack. (CVE-2021-44224)\n\n It was discovered that the Apache HTTP Server Lua module incorrectly\n handled memory in the multipart parser. A remote attacker could use this\n issue to cause the server to crash, resulting in a denial of service, or\n possibly execute arbitrary code. (CVE-2021-44790)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm3","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-44790","CVE-2021-44224"]}]},{"id":"CVE-2021-44224","published":"2021-12-20T00:00:00","updated_at":"2025-08-25T23:42:52.988006+00:00","description":"\nA crafted URI sent to httpd configured as a forward proxy (ProxyRequests\non) can cause a crash (NULL pointer dereference) or, for configurations\nmixing forward and reverse proxy declarations, can allow for requests to be\ndirected to a declared Unix Domain Socket endpoint (Server Side Request\nForgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51\n(included).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fixed by r1895955+r1896044 in 2.4.x"}],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://httpd.apache.org/security/vulnerabilities_24.html","https://ubuntu.com/security/notices/USN-5212-1","https://ubuntu.com/security/notices/USN-5212-2","https://www.cve.org/CVERecord?id=CVE-2021-44224"],"bugs":[""],"patches":{"apache2":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1895955","upstream: https://svn.apache.org/viewvc?view=revision&revision=1896044","upstream: https://github.com/apache/httpd/commit/a962ba73047b5478d702c8ad09fd1a167e1d3736","upstream: https://github.com/apache/httpd/commit/a0521d289ae14e4ac004811dc1ef91b3e118a2f6"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.21","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"2.4.46-4ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2.4.48-3.1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.52","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm4","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-5212-1","USN-5212-2"],"notices":[{"id":"USN-5212-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-01-06T14:48:19.125348","description":"It was discovered that the Apache HTTP Server incorrectly handled certain\nforward proxy requests. A remote attacker could use this issue to cause\nthe server to crash, resulting in a denial of service, or possibly perform\na Server Side Request Forgery attack. (CVE-2021-44224)\n\nIt was discovered that the Apache HTTP Server Lua module incorrectly\nhandled memory in the multipart parser. A remote attacker could use this\nissue to cause the server to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2021-44790)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"apache2","version":"2.4.46-4ubuntu1.5","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-utils","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-dev","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-doc","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"},{"name":"apache2-bin","version":"2.4.46-4ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.46-4ubuntu1.5","pocket":"security"}],"impish":[{"name":"apache2","version":"2.4.48-3.1ubuntu3.2","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-utils","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-dev","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-doc","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"},{"name":"apache2-bin","version":"2.4.48-3.1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.48-3.1ubuntu3.2","pocket":"security"}],"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.21","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.29-1ubuntu4.21","pocket":"security"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.9","description":"Apache HTTP server","is_source":true},{"name":"apache2-data","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.41-4ubuntu3.9","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-44790","CVE-2021-44224"]},{"id":"USN-5212-2","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-01-10T11:14:47.876943","description":"USN-5212-1 fixed several vulnerabilities in Apache. This update provides\nthe corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that the Apache HTTP Server incorrectly handled certain\n forward proxy requests. A remote attacker could use this issue to cause\n the server to crash, resulting in a denial of service, or possibly perform\n a Server Side Request Forgery attack. (CVE-2021-44224)\n\n It was discovered that the Apache HTTP Server Lua module incorrectly\n handled memory in the multipart parser. A remote attacker could use this\n issue to cause the server to crash, resulting in a denial of service, or\n possibly execute arbitrary code. (CVE-2021-44790)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm3","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-44790","CVE-2021-44224"]}]},{"id":"CVE-2021-4136","published":"2021-12-19T17:15:00","updated_at":"2025-08-25T23:41:54.247336+00:00","description":"\nvim is vulnerable to Heap-based Buffer Overflow","ubuntu_description":"","notes":[{"author":"ccdm94","note":"introduced by commit 2949cfdbe433 (>= 8.2.2257)."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/5c6b93c1-2d27-4e98-a931-147877b8c938","https://github.com/vim/vim/commit/605ec91e5a7330d61be313637e495fa02a6dc264","https://www.cve.org/CVERecord?id=CVE-2021-4136"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1002534"],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/605ec91e5a7330d61be313637e495fa02a6dc264"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.2.3847","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2:8.2.3995-1ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-45105","published":"2021-12-19T00:00:00","updated_at":"2025-08-26T12:36:58.917433+00:00","description":"\nApache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and\n2.3.1) did not protect from uncontrolled recursion from self-referential\nlookups. This allows an attacker with control over Thread Context Map data\nto cause a denial of service when a crafted string is interpreted. This\nissue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell","https://logging.apache.org/log4j/2.x/security.html#CVE-2021-45105","https://ubuntu.com/security/notices/USN-5203-1","https://ubuntu.com/security/notices/USN-5222-1","https://www.cve.org/CVERecord?id=CVE-2021-45105"],"bugs":[""],"patches":{"apache-log4j2":["upstream: https://github.com/apache/logging-log4j2/commit/806023265f8c905b2dd1d81fd2458f64b2ea0b5e","upstream: https://github.com/apache/logging-log4j2/commit/bf7e916df6335713fe2219c7b3b523fb509deabc"]},"tags":{},"packages":[{"name":"apache-log4j2","source":"https://ubuntu.com/security/cve?package=apache-log4j2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache-log4j2","debian":"https://tracker.debian.org/pkg/apache-log4j2","statuses":[{"release_codename":"bionic","status":"released","description":"2.12.4-0ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.17.0-0.20.04.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"2.17.0-0.21.04.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2.17.0-0.21.10.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.17.0-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5203-1","USN-5222-1"],"notices":[{"id":"USN-5203-1","title":"Apache Log4j 2 vulnerability","summary":"Apache Log4j 2 could be made to crash if it received specially crafted\ninput.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-19T17:39:38.583910","description":"Hideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not\nprotect against infinite recursion in lookup evaluation. A remote attacker\ncould possibly use this issue to cause Apache Log4j 2 to crash, leading to\na denial of service.\nPlease see the following link for more information:\nhttps://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"apache-log4j2","version":"2.17.0-0.21.04.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.17.0-0.21.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.0-0.21.04.1","pocket":"security"}],"impish":[{"name":"apache-log4j2","version":"2.17.0-0.21.10.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.17.0-0.21.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.0-0.21.10.1","pocket":"security"}],"focal":[{"name":"apache-log4j2","version":"2.17.0-0.20.04.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.17.0-0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.0-0.20.04.1","pocket":"security"},{"name":"liblog4j2-java-doc","version":"2.17.0-0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.0-0.20.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-45105"]},{"id":"USN-5222-1","title":"Apache Log4j 2 vulnerabilities","summary":"Several security issues were fixed in Apache Log4j 2.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-01-11T20:42:28.819811","description":"It was discovered that Apache Log4j 2 was vulnerable to remote code\nexecution (RCE) attack when configured to use a JDBC Appender with a\nJNDI LDAP data source URI. A remote attacker could possibly use this issue to\ncause a crash, leading to a denial of service. (CVE-2021-44832)\n\nHideki Okamoto and Guy Lederfein discovered that Apache Log4j 2 did not\nprotect against infinite recursion in lookup evaluation. A remote attacker\ncould possibly use this issue to cause Apache Log4j 2 to crash, leading to\na denial of service. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2021-45105)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"apache-log4j2","version":"2.17.1-0.21.04.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.17.1-0.21.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.1-0.21.04.1","pocket":"security"}],"impish":[{"name":"apache-log4j2","version":"2.17.1-0.21.10.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.17.1-0.21.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.1-0.21.10.1","pocket":"security"}],"bionic":[{"name":"apache-log4j2","version":"2.12.4-0ubuntu0.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.12.4-0ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.12.4-0ubuntu0.1","pocket":"security"},{"name":"liblog4j2-java-doc","version":"2.12.4-0ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.12.4-0ubuntu0.1","pocket":"security"}],"focal":[{"name":"apache-log4j2","version":"2.17.1-0.20.04.1","description":"Apache Log4j - Logging Framework for Java","is_source":true},{"name":"liblog4j2-java","version":"2.17.1-0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.1-0.20.04.1","pocket":"security"},{"name":"liblog4j2-java-doc","version":"2.17.1-0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache-log4j2","version_link":"https://launchpad.net/ubuntu/+source/apache-log4j2/2.17.1-0.20.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-44832","CVE-2021-45105"]}]},{"id":"CVE-2021-41500","published":"2021-12-17T21:15:00","updated_at":"2025-08-26T12:35:20.005659+00:00","description":"\nIncomplete string comparison vulnerability exits in cvxopt.org cvxop <=\n1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor,\ncvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to\nconduct Denial of Service attacks by construct fake Capsule objects.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/cvxopt/cvxopt/issues/193","https://www.cve.org/CVERecord?id=CVE-2021-41500"],"bugs":[""],"patches":{"cvxopt":[]},"tags":{},"packages":[{"name":"cvxopt","source":"https://ubuntu.com/security/cve?package=cvxopt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cvxopt","debian":"https://tracker.debian.org/pkg/cvxopt","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.7+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.2.7+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-41499","published":"2021-12-17T21:15:00","updated_at":"2025-08-26T12:35:20.005659+00:00","description":"\nBuffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in\nthe Server_debug function, which allows remote attackers to conduct DoS\nattacks by deliberately passing on an overlong audio file name.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/belangeo/pyo/issues/222","https://github.com/belangeo/pyo/commit/e7e6d2880469b523e4c41f0da2087a6a3eec4a45 (1.0.4)","https://www.cve.org/CVERecord?id=CVE-2021-41499"],"bugs":[""],"patches":{"python-pyo":[]},"tags":{},"packages":[{"name":"python-pyo","source":"https://ubuntu.com/security/cve?package=python-pyo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pyo","debian":"https://tracker.debian.org/pkg/python-pyo","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-41498","published":"2021-12-17T21:15:00","updated_at":"2025-08-26T12:35:20.005659+00:00","description":"\nBuffer overflow in ajaxsoundstudio.com Pyo < and 1.03 in the\nServer_jack_init function. which allows attackers to conduct Denial of\nService attacks by arbitrary constructing a overlong server name.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/belangeo/pyo/issues/221","https://github.com/belangeo/pyo/commit/017702c73332a8560c8554a36250a6da587a2418 (1.0.4)","https://www.cve.org/CVERecord?id=CVE-2021-41498"],"bugs":[""],"patches":{"python-pyo":[]},"tags":{},"packages":[{"name":"python-pyo","source":"https://ubuntu.com/security/cve?package=python-pyo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pyo","debian":"https://tracker.debian.org/pkg/python-pyo","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.0.4-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-41496","published":"2021-12-17T20:15:00","updated_at":"2025-08-04T19:35:43.740836+00:00","description":"\nBuffer overflow in the array_from_pyobj function of fortranobject.c in\nNumPy < 1.19, which allows attackers to conduct a Denial of Service attacks\nby carefully constructing an array with negative values. NOTE: The vendor\ndoes not agree this is a vulnerability; the negative dimensions can only be\ncreated by an already privileged user (or internally)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/numpy/numpy/issues/19000","https://github.com/numpy/numpy/pull/20630","https://github.com/numpy/numpy/commit/271010f1037150e95017f803f4214b8861e528f2","https://ubuntu.com/security/notices/USN-5763-1","https://www.cve.org/CVERecord?id=CVE-2021-41496"],"bugs":[""],"patches":{"numpy":["upstream: https://github.com/numpy/numpy/commit/271010f1037150e95017f803f4214b8861e528f2"]},"tags":{},"packages":[{"name":"numpy","source":"https://ubuntu.com/security/cve?package=numpy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=numpy","debian":"https://tracker.debian.org/pkg/numpy","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:1.21.5-1ubuntu22.04.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1:1.21.5-1ubuntu22.10.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.24.1-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.17.4-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.22.0, 1.23.0","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-5763-1"],"notices":[{"id":"USN-5763-1","title":"NumPy vulnerabilities","summary":"Several security issues were fixed in NumPy.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-12-07T05:01:48.350125","description":"It was discovered that NumPy did not properly manage memory when specifying\narrays of large dimensions. If a user were tricked into running malicious\nPython file, an attacker could cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2021-33430)\n\nIt was discovered that NumPy did not properly perform string comparison\noperations under certain circumstances. An attacker could possibly use\nthis issue to cause NumPy to crash, resulting in a denial of service.\n(CVE-2021-34141)\n\nIt was discovered that NumPy did not properly manage memory under certain\ncircumstances. An attacker could possibly use this issue to cause NumPy to\ncrash, resulting in a denial of service. (CVE-2021-41495, CVE-2021-41496)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"numpy","version":"1:1.21.5-1ubuntu22.10.1","description":"scientific computing package with Python","is_source":true},{"name":"python-numpy-doc","version":"1:1.21.5-1ubuntu22.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.10.1","pocket":"security"},{"name":"python3-numpy","version":"1:1.21.5-1ubuntu22.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.10.1","pocket":"security"}],"jammy":[{"name":"numpy","version":"1:1.21.5-1ubuntu22.04.1","description":"scientific computing package with Python","is_source":true},{"name":"python-numpy-doc","version":"1:1.21.5-1ubuntu22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.04.1","pocket":"security"},{"name":"python3-numpy","version":"1:1.21.5-1ubuntu22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.04.1","pocket":"security"}],"focal":[{"name":"numpy","version":"1:1.17.4-5ubuntu3.1","description":"scientific computing package with Python","is_source":true},{"name":"python-numpy-doc","version":"1:1.17.4-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.17.4-5ubuntu3.1","pocket":"security"},{"name":"python3-numpy","version":"1:1.17.4-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.17.4-5ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-41495","CVE-2021-34141","CVE-2021-41496","CVE-2021-33430"]}]},{"id":"CVE-2021-41495","published":"2021-12-17T20:15:00","updated_at":"2025-08-04T19:35:43.740836+00:00","description":"\nNull Pointer Dereference vulnerability exists in numpy.sort in NumPy <\nand 1.19 in the PyArray_DescrNew function due to missing return-value\nvalidation, which allows attackers to conduct DoS attacks by repetitively\ncreating sort arrays. NOTE: While correct that validation is missing, an\nerror can only occur due to an exhaustion of memory. If the user can\nexhaust memory, they are already privileged. Further, it should be\npractically impossible to construct an attack which can target the memory\nexhaustion to occur at exactly this place","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/numpy/numpy/issues/19038","https://github.com/numpy/numpy/pull/20984 (backport)","https://github.com/numpy/numpy/pull/20960","https://ubuntu.com/security/notices/USN-5763-1","https://www.cve.org/CVERecord?id=CVE-2021-41495"],"bugs":[""],"patches":{"numpy":[]},"tags":{},"packages":[{"name":"numpy","source":"https://ubuntu.com/security/cve?package=numpy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=numpy","debian":"https://tracker.debian.org/pkg/numpy","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:1.24.1-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.17.4-5ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.22.2, 1.23.0","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:1.21.5-1ubuntu22.04.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1:1.21.5-1ubuntu22.10.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5763-1"],"notices":[{"id":"USN-5763-1","title":"NumPy vulnerabilities","summary":"Several security issues were fixed in NumPy.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-12-07T05:01:48.350125","description":"It was discovered that NumPy did not properly manage memory when specifying\narrays of large dimensions. If a user were tricked into running malicious\nPython file, an attacker could cause a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2021-33430)\n\nIt was discovered that NumPy did not properly perform string comparison\noperations under certain circumstances. An attacker could possibly use\nthis issue to cause NumPy to crash, resulting in a denial of service.\n(CVE-2021-34141)\n\nIt was discovered that NumPy did not properly manage memory under certain\ncircumstances. An attacker could possibly use this issue to cause NumPy to\ncrash, resulting in a denial of service. (CVE-2021-41495, CVE-2021-41496)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"numpy","version":"1:1.21.5-1ubuntu22.10.1","description":"scientific computing package with Python","is_source":true},{"name":"python-numpy-doc","version":"1:1.21.5-1ubuntu22.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.10.1","pocket":"security"},{"name":"python3-numpy","version":"1:1.21.5-1ubuntu22.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.10.1","pocket":"security"}],"jammy":[{"name":"numpy","version":"1:1.21.5-1ubuntu22.04.1","description":"scientific computing package with Python","is_source":true},{"name":"python-numpy-doc","version":"1:1.21.5-1ubuntu22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.04.1","pocket":"security"},{"name":"python3-numpy","version":"1:1.21.5-1ubuntu22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.21.5-1ubuntu22.04.1","pocket":"security"}],"focal":[{"name":"numpy","version":"1:1.17.4-5ubuntu3.1","description":"scientific computing package with Python","is_source":true},{"name":"python-numpy-doc","version":"1:1.17.4-5ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.17.4-5ubuntu3.1","pocket":"security"},{"name":"python3-numpy","version":"1:1.17.4-5ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/numpy","version_link":"https://launchpad.net/ubuntu/+source/numpy/1:1.17.4-5ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-41495","CVE-2021-34141","CVE-2021-41496","CVE-2021-33430"]}]},{"id":"CVE-2021-23803","published":"2021-12-17T20:15:00","updated_at":"2025-08-26T12:29:22.479283+00:00","description":"\nThis affects the package latte/latte before 2.10.6. There is a way to\nbypass allowFunctions that will affect the security of the application.\nWhen the template is set to allow/disallow the use of certain functions,\nadding control characters (x00-x08) after the function will bypass these\nrestrictions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/nette/latte/commit/227c86eda9a8a6d060ea8501923e768b6d992210","https://github.com/nette/latte/issues/279","https://snyk.io/vuln/SNYK-PHP-LATTELATTE-1932226","https://www.cve.org/CVERecord?id=CVE-2021-23803"],"bugs":[""],"patches":{"php-nette":[]},"tags":{},"packages":[{"name":"php-nette","source":"https://ubuntu.com/security/cve?package=php-nette","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-nette","debian":"https://tracker.debian.org/pkg/php-nette","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-23797","published":"2021-12-17T20:15:00","updated_at":"2025-07-11T07:46:26.946278+00:00","description":"\nAll versions of package http-server-node are vulnerable to Directory\nTraversal via use of --path-as-is.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://security.snyk.io/vuln/SNYK-JS-HTTPSERVERNODE-1727656","https://www.cve.org/CVERecord?id=CVE-2021-23797"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1031301"],"patches":{"node-http-server":[]},"tags":{},"packages":[{"name":"node-http-server","source":"https://ubuntu.com/security/cve?package=node-http-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-http-server","debian":"https://tracker.debian.org/pkg/node-http-server","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":40400,"limit":20,"total_results":79316}