{"cves":[{"id":"CVE-2021-42379","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:17.345318+00:00","description":"\nA use-after-free in Busybox's awk applet leads to denial of service and\npossibly code execution when processing a crafted awk pattern in the\nnext_input_file function","ubuntu_description":"","notes":[{"author":"ccdm94","note":"fix (importing awk.c from busybox version >= 1.34.0 due to large\namount of changes made to the awk.c code) introduces a regression\nto busybox awk in xenial and earlier. Applying changes from the\ncommit which prevents this regression from happening (237bedd499c)\ncould result in further regressions being introduced to other\napplets in busybox. This happens because interfaces for applets\nare altered in this commit, and the calls to get them executed\nthrough busybox are modified. External applications which use\nbusybox could end up with regressions as well because of this."}],"codename":null,"priority":"low","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://ubuntu.com/security/notices/USN-5179-1","https://www.cve.org/CVERecord?id=CVE-2021-42379"],"bugs":[""],"patches":{"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.30.1-4ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:1.30.1-6ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1:1.30.1-6ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:1.30.1-7ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":["USN-5179-1"],"notices":[{"id":"USN-5179-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-07T12:44:40.275268","description":"It was discovered that BusyBox incorrectly handled certain malformed gzip\narchives. If a user or automated system were tricked into processing a\nspecially crafted gzip archive, a remote attacker could use this issue to\ncause BusyBox to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2021-28831)\n\nIt was discovered that BusyBox incorrectly handled certain malformed LZMA\narchives. If a user or automated system were tricked into processing a\nspecially crafted LZMA archive, a remote attacker could use this issue to\ncause BusyBox to crash, resulting in a denial of service, or possibly\nleak sensitive information. (CVE-2021-42374)\n\nVera Mens, Uri Katz, Tal Keren, Sharon Brizinov, and Shachar Menashe\ndiscovered that BusyBox incorrectly handled certain awk patterns. If a user\nor automated system were tricked into processing a specially crafted awk\npattern, a remote attacker could use this issue to cause BusyBox to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,\nCVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"busybox","version":"1:1.30.1-6ubuntu2.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"}],"impish":[{"name":"busybox","version":"1:1.30.1-6ubuntu3.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"}],"focal":[{"name":"busybox","version":"1:1.30.1-4ubuntu6.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"}],"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-28831","CVE-2021-42378","CVE-2021-42386","CVE-2021-42385","CVE-2021-42382","CVE-2021-42384","CVE-2021-42379","CVE-2021-42374","CVE-2021-42380","CVE-2021-42381"]}]},{"id":"CVE-2021-42378","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:17.345318+00:00","description":"\nA use-after-free in Busybox's awk applet leads to denial of service and\npossibly code execution when processing a crafted awk pattern in the\ngetvar_i function","ubuntu_description":"","notes":[{"author":"ccdm94","note":"fix (importing awk.c from busybox version >= 1.34.0 due to large\namount of changes made to the awk.c code) introduces a regression\nto busybox awk in xenial and earlier. Applying changes from the\ncommit which prevents this regression from happening (237bedd499c)\ncould result in further regressions being introduced to other\napplets in busybox. This happens because interfaces for applets\nare altered in this commit, and the calls to get them executed\nthrough busybox are modified. External applications which use\nbusybox could end up with regressions as well because of this."}],"codename":null,"priority":"low","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://ubuntu.com/security/notices/USN-5179-1","https://www.cve.org/CVERecord?id=CVE-2021-42378"],"bugs":[""],"patches":{"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.30.1-4ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:1.30.1-6ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1:1.30.1-6ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:1.30.1-7ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":["USN-5179-1"],"notices":[{"id":"USN-5179-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-07T12:44:40.275268","description":"It was discovered that BusyBox incorrectly handled certain malformed gzip\narchives. If a user or automated system were tricked into processing a\nspecially crafted gzip archive, a remote attacker could use this issue to\ncause BusyBox to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2021-28831)\n\nIt was discovered that BusyBox incorrectly handled certain malformed LZMA\narchives. If a user or automated system were tricked into processing a\nspecially crafted LZMA archive, a remote attacker could use this issue to\ncause BusyBox to crash, resulting in a denial of service, or possibly\nleak sensitive information. (CVE-2021-42374)\n\nVera Mens, Uri Katz, Tal Keren, Sharon Brizinov, and Shachar Menashe\ndiscovered that BusyBox incorrectly handled certain awk patterns. If a user\nor automated system were tricked into processing a specially crafted awk\npattern, a remote attacker could use this issue to cause BusyBox to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,\nCVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"busybox","version":"1:1.30.1-6ubuntu2.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"}],"impish":[{"name":"busybox","version":"1:1.30.1-6ubuntu3.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"}],"focal":[{"name":"busybox","version":"1:1.30.1-4ubuntu6.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"}],"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-28831","CVE-2021-42378","CVE-2021-42386","CVE-2021-42385","CVE-2021-42382","CVE-2021-42384","CVE-2021-42379","CVE-2021-42374","CVE-2021-42380","CVE-2021-42381"]}]},{"id":"CVE-2021-42377","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:13.096378+00:00","description":"\nAn attacker-controlled pointer free in Busybox's hush applet leads to\ndenial of service and possible code execution when processing a crafted\nshell command, due to the shell mishandling the &&& string. This may be\nused for remote code execution under rare conditions of filtered command\ninput.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"1.33.0+"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://www.cve.org/CVERecord?id=CVE-2021-42377"],"bugs":[""],"patches":{"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"1:1.30.1-6ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:1.30.1-6ubuntu3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:1.30.1-6ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.2-2ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.30.1-4ubuntu6.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-42376","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:13.096378+00:00","description":"\nA NULL pointer dereference in Busybox's hush applet leads to denial of\nservice when processing a crafted shell command, due to missing validation\nafter a \\x03 delimiter character. This may be used for DoS under very rare\nconditions of filtered command input.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hush is not build in Ubuntu packages."}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://www.cve.org/CVERecord?id=CVE-2021-42376"],"bugs":[""],"patches":{"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-42375","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:13.096378+00:00","description":"\nAn incorrect handling of a special element in Busybox's ash applet leads to\ndenial of service when processing a crafted shell command, due to the shell\nmistaking specific characters for reserved characters. This may be used for\nDoS under rare conditions of filtered command input.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"1.33.1 only"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://www.cve.org/CVERecord?id=CVE-2021-42375"],"bugs":[""],"patches":{"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"bionic","status":"not-affected","description":"1:1.27.2-2ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.30.1-4ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:1.30.1-6ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:1.30.1-6ubuntu3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:1.30.1-6ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-42374","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:13.096378+00:00","description":"\nAn out-of-bounds heap read in Busybox's unlzma applet leads to information\nleak and denial of service when crafted LZMA-compressed input is\ndecompressed. This can be triggered by any applet/format that","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.27.0"}],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://ubuntu.com/security/notices/USN-5179-1","https://www.cve.org/CVERecord?id=CVE-2021-42374"],"bugs":[""],"patches":{"busybox":["upstream: https://git.busybox.net/busybox/commit/?id=04f052c56ded5ab6a904e3a264a73dc0412b2e78"]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.30.1-4ubuntu6.4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:1.30.1-6ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1:1.30.1-6ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:1.30.1-7ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5179-1"],"notices":[{"id":"USN-5179-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-07T12:44:40.275268","description":"It was discovered that BusyBox incorrectly handled certain malformed gzip\narchives. If a user or automated system were tricked into processing a\nspecially crafted gzip archive, a remote attacker could use this issue to\ncause BusyBox to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2021-28831)\n\nIt was discovered that BusyBox incorrectly handled certain malformed LZMA\narchives. If a user or automated system were tricked into processing a\nspecially crafted LZMA archive, a remote attacker could use this issue to\ncause BusyBox to crash, resulting in a denial of service, or possibly\nleak sensitive information. (CVE-2021-42374)\n\nVera Mens, Uri Katz, Tal Keren, Sharon Brizinov, and Shachar Menashe\ndiscovered that BusyBox incorrectly handled certain awk patterns. If a user\nor automated system were tricked into processing a specially crafted awk\npattern, a remote attacker could use this issue to cause BusyBox to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2021-42378, CVE-2021-42379, CVE-2021-42380, CVE-2021-42381,\nCVE-2021-42382, CVE-2021-42384, CVE-2021-42385, CVE-2021-42386)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"busybox","version":"1:1.30.1-6ubuntu2.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-6ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu2.1","pocket":"security"}],"impish":[{"name":"busybox","version":"1:1.30.1-6ubuntu3.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-6ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-6ubuntu3.1","pocket":"security"}],"focal":[{"name":"busybox","version":"1:1.30.1-4ubuntu6.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-4ubuntu6.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.4","pocket":"security"}],"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-28831","CVE-2021-42378","CVE-2021-42386","CVE-2021-42385","CVE-2021-42382","CVE-2021-42384","CVE-2021-42379","CVE-2021-42374","CVE-2021-42380","CVE-2021-42381"]}]},{"id":"CVE-2021-42373","published":"2021-11-15T21:15:00","updated_at":"2025-08-25T23:42:13.096378+00:00","description":"\nA NULL pointer dereference in Busybox's man applet leads to denial of\nservice when a section name is supplied but no page argument is given","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.33"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://jfrog.com/blog/unboxing-busybox-14-new-vulnerabilities-uncovered-by-claroty-and-jfrog/","https://www.cve.org/CVERecord?id=CVE-2021-42373"],"bugs":[""],"patches":{"busybox":[]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"jammy","status":"not-affected","description":"1:1.30.1-6ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.34.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.2-2ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:1.30.1-4ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:1.30.1-6ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:1.30.1-6ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-41244","published":"2021-11-15T20:15:00","updated_at":"2025-08-26T12:35:20.005659+00:00","description":"\nGrafana is an open-source platform for monitoring and observability. In\naffected versions when the fine-grained access control beta feature is\nenabled and there is more than one organization in the Grafana instance\nadmins are able to access users from other organizations. Grafana 8.0\nintroduced a mechanism which allowed users with the Organization Admin role\nto list, add, remove, and update users’ roles in other organizations in\nwhich they are not an admin. With fine-grained access control enabled,\norganization admins can list, add, remove and update users' roles in\nanother organization, where they do not have organization admin role. All\ninstallations between v8.0 and v8.2.3 that have fine-grained access control\nbeta enabled and more than one organization should be upgraded as soon as\npossible. If you cannot upgrade, you should turn off the fine-grained\naccess control using a feature flag.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Xenial's grafana pacakge doesn't appear to have fine grained acls"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://grafana.com/blog/2021/11/15/grafana-8.2.4-released-with-security-fixes/","https://github.com/grafana/grafana/security/advisories/GHSA-mpwp-42x6-4wmx","http://www.openwall.com/lists/oss-security/2021/11/15/1","https://www.cve.org/CVERecord?id=CVE-2021-41244"],"bugs":[""],"patches":{"grafana":[]},"tags":{},"packages":[{"name":"grafana","source":"https://ubuntu.com/security/cve?package=grafana","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grafana","debian":"https://tracker.debian.org/pkg/grafana","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-22959","published":"2021-11-15T15:15:00","updated_at":"2025-08-25T23:33:15.859177+00:00","description":"\nThe parser in accepts requests with a space (SP) right after the header\nname before the colon. This can lead to HTTP Request Smuggling (HRS) in\nllhttp < v2.1.4 and < v6.0.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://nodejs.org/en/blog/vulnerability/oct-2021-security-releases/#http-request-smuggling-due-to-spaced-in-headers-medium-cve-2021-22959","https://www.cve.org/CVERecord?id=CVE-2021-22959"],"bugs":[""],"patches":{"nodejs":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"12.22.7~dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"12.22.9~dfsg-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"18.7.0+dfsg-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"18.7.0+dfsg-5ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-43618","published":"2021-11-15T04:15:00","updated_at":"2025-08-25T23:42:48.624499+00:00","description":"\nGNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an\nmpz/inp_raw.c integer overflow and resultant buffer overflow via crafted\ninput, leading to a segmentation fault on 32-bit platforms.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reproducer in debian bug report"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gmplib.org/list-archives/gmp-bugs/2021-September/005077.html","https://ubuntu.com/security/notices/USN-5672-1","https://ubuntu.com/security/notices/USN-5672-2","https://www.cve.org/CVERecord?id=CVE-2021-43618"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=994405"],"patches":{"gmp":["upstream: https://gmplib.org/repo/gmp-6.2/rev/561a9c25298e"]},"tags":{},"packages":[{"name":"gmp","source":"https://ubuntu.com/security/cve?package=gmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gmp","debian":"https://tracker.debian.org/pkg/gmp","statuses":[{"release_codename":"focal","status":"released","description":"2:6.2.0+dfsg-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2:6.2.1+dfsg-3ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2:6.2.1+dfsg1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:6.2.1+dfsg1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:5.1.3+dfsg-1ubuntu1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2:6.1.0+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:6.2.1+dfsg-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:6.1.2+dfsg-2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5672-1","USN-5672-2"],"notices":[{"id":"USN-5672-1","title":"GMP vulnerability","summary":"GMP could be made to crash if it received specially crafted\ninput.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-10-12T12:54:58.792040","description":"It was discovered that GMP did not properly manage memory\non 32-bit platforms when processing a specially crafted\ninput. An attacker could possibly use this issue to cause\napplications using GMP to crash, resulting in a denial of\nservice.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gmp","version":"2:6.1.2+dfsg-2ubuntu0.1","description":"Multiprecision arithmetic library developers tools","is_source":true},{"name":"libgmp10-doc","version":"2:6.1.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libgmpxx4ldbl","version":"2:6.1.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libgmp-dev","version":"2:6.1.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libgmp10","version":"2:6.1.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1","pocket":"security"},{"name":"libgmp3-dev","version":"2:6.1.2+dfsg-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.1.2+dfsg-2ubuntu0.1","pocket":"security"}],"focal":[{"name":"gmp","version":"2:6.2.0+dfsg-4ubuntu0.1","description":"Multiprecision arithmetic library developers tools","is_source":true},{"name":"libgmp10-doc","version":"2:6.2.0+dfsg-4ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1","pocket":"security"},{"name":"libgmpxx4ldbl","version":"2:6.2.0+dfsg-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1","pocket":"security"},{"name":"libgmp-dev","version":"2:6.2.0+dfsg-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1","pocket":"security"},{"name":"libgmp10","version":"2:6.2.0+dfsg-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1","pocket":"security"},{"name":"libgmp3-dev","version":"2:6.2.0+dfsg-4ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":"https://launchpad.net/ubuntu/+source/gmp/2:6.2.0+dfsg-4ubuntu0.1","pocket":"security"}],"xenial":[{"name":"gmp","version":"2:6.1.0+dfsg-2ubuntu0.1~esm1","description":"Multiprecision arithmetic library developers tools","is_source":true},{"name":"libgmp10-doc","version":"2:6.1.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmpxx4ldbl","version":"2:6.1.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmp-dev","version":"2:6.1.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmp10","version":"2:6.1.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmp3-dev","version":"2:6.1.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-43618"]},{"id":"USN-5672-2","title":"GMP vulnerability","summary":"GMP could be made to crash if it received specially crafted\ninput.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-06T14:27:26.536039","description":"USN-5672-1 fixed a vulnerability in GMP. This update provides\nthe corresponsing update for Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GMP did not properly manage memory\n on 32-bit platforms when processing a specially crafted\n input. An attacker could possibly use this issue to cause\n applications using GMP to crash, resulting in a denial of\n service.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"gmp","version":"2:5.1.3+dfsg-1ubuntu1+esm1","description":"Multiprecision arithmetic library developers tools","is_source":true},{"name":"libgmp10-doc","version":"2:5.1.3+dfsg-1ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmpxx4ldbl","version":"2:5.1.3+dfsg-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmp3-dev","version":"2:5.1.3+dfsg-1ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmp10","version":"2:5.1.3+dfsg-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"},{"name":"libgmp-dev","version":"2:5.1.3+dfsg-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gmp","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-43618"]}]},{"id":"CVE-2020-14424","published":"2021-11-14T20:15:00","updated_at":"2025-08-25T23:20:45.753176+00:00","description":"\nCacti before 1.2.18 allows remote attackers to trigger XSS via template\nimport for the midwinter theme.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"d12800ab479 landed in 1.2.18, 0234c1b645d in 1.2.12, which\nfixed XSS in other themes."}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Cacti/cacti/pull/4261","https://github.com/Cacti/cacti/commit/d12800ab479ad95a091bc577f28fd99ec95eb64c (release/1.2.18)","https://bugzilla.redhat.com/show_bug.cgi?id=2001016","https://ubuntu.com/security/notices/USN-5214-1","https://www.cve.org/CVERecord?id=CVE-2020-14424"],"bugs":[""],"patches":{"cacti":["upstream: https://github.com/Cacti/cacti/commit/d12800ab479ad95a091bc577f28fd99ec95eb64c","upstream: https://github.com/Cacti/cacti/commit/0234c1b645d4c9a77ce6fe9811e50b39dd32116f"]},"tags":{},"packages":[{"name":"cacti","source":"https://ubuntu.com/security/cve?package=cacti","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cacti","debian":"https://tracker.debian.org/pkg/cacti","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.1.38+ds1-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.2.10+ds1-1ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.18","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.2.16+ds1-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5214-1"],"notices":[{"id":"USN-5214-1","title":"Cacti vulnerabilities","summary":"Several security issues were fixed in Cacti.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-06-09T09:14:15.350841","description":"It was discovered that Cacti was incorrectly validating permissions\nfor user accounts that had been recently disabled. An authenticated\nattacker could possibly use this to obtain unauthorized access to\napplication and system data. (CVE-2020-13230)\n\nIt was discovered that Cacti was incorrectly performing authorization\nchecks in auth_profile.php. A remote unauthenticated attacker could\nuse this to perform a CSRF attack and set a new admin email or make\nother changes. This issue only affected Ubuntu 18.04 ESM and\nUbuntu 20.04 ESM. (CVE-2020-13231)\n\nIt was discovered that Cacti incorrectly handled user provided input\nsent through request parameters to the color.php script. A remote\nauthenticated attacker could use this issue to perform SQL injection\nattacks. This issue only affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM.\n(CVE-2020-14295)\n\nIt was discovered that Cacti did not properly escape file input fields\nwhen performing template import operations for various themes. An\nauthenticated attacker could use this to perform XSS attacks. This issue\nonly affected Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-14424)\n\nIt was discovered that Cacti incorrectly handled user provided input\nsent through request parameters to the data_debug.php script. A remote\nauthenticated attacker could use this issue to perform SQL injection\nattacks. This issue only affected Ubuntu 20.04 ESM. (CVE-2020-35701)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"cacti","version":"1.1.38+ds1-1ubuntu0.1~esm1","description":"web interface for graphing of monitoring systems","is_source":true},{"name":"cacti","version":"1.1.38+ds1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cacti","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"cacti","version":"1.2.10+ds1-1ubuntu1+esm1","description":"web interface for graphing of monitoring systems","is_source":true},{"name":"cacti","version":"1.2.10+ds1-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cacti","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"cacti","version":"0.8.8f+ds1-4ubuntu4.16.04.2+esm1","description":"web interface for graphing of monitoring systems","is_source":true},{"name":"cacti","version":"0.8.8f+ds1-4ubuntu4.16.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cacti","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-14424","CVE-2020-35701","CVE-2020-13230","CVE-2020-14295","CVE-2020-13231"]}]},{"id":"CVE-2021-43617","published":"2021-11-14T16:15:00","updated_at":"2025-08-25T23:42:48.624499+00:00","description":"\nLaravel Framework through 8.70.2 does not sufficiently block the upload of\nexecutable PHP content because\nIlluminate/Validation/Concerns/ValidatesAttributes.php lacks a check for\n.phar files, which are handled as application/x-httpd-php on systems based\non Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated\nto any reports concerning incorrectly written user applications for image\nupload.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://hosein-vita.medium.com/laravel-8-x-image-upload-bypass-zero-day-852bd806019b","https://salsa.debian.org/php-team/php/-/blob/dc253886b5b2e9bc8d9e36db787abb083a667fd8/debian/php-cgi.conf#L5-6","https://github.com/laravel/framework/blob/2049de73aa099a113a287587df4cc522c90961f5/src/Illuminate/Validation/Concerns/ValidatesAttributes.php#L1331-L1333","https://salsa.debian.org/php-team/php/-/commit/dc253886b5b2e9bc8d9e36db787abb083a667fd8","https://www.cve.org/CVERecord?id=CVE-2021-43617"],"bugs":[""],"patches":{"php-laravel-framework":[]},"tags":{},"packages":[{"name":"php-laravel-framework","source":"https://ubuntu.com/security/cve?package=php-laravel-framework","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-laravel-framework","debian":"https://tracker.debian.org/pkg/php-laravel-framework","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-43616","published":"2021-11-13T18:15:00","updated_at":"2025-08-04T18:13:42.394851+00:00","description":"\nThe npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an\ninstallation even if dependency information in package-lock.json differs\nfrom package.json. This behavior is inconsistent with the documentation,\nand makes it easier for attackers to install malware that was supposed to\nhave been blocked by an exact version match requirement in\npackage-lock.json. NOTE: The npm team believes this is not a vulnerability.\nIt would require someone to socially engineer package.json which has\ndifferent dependencies than package-lock.json. That user would have to have\nfile system or write access to change dependencies. The npm team states\npreventing malicious actors from socially engineering or gaining file\nsystem access is outside the scope of the npm CLI.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/npm/cli/issues/2701","https://docs.npmjs.com/cli/v7/commands/npm-ci","https://github.com/icatalina/CVE-2021-43616","https://www.cve.org/CVERecord?id=CVE-2021-43616"],"bugs":[""],"patches":{"npm":[]},"tags":{},"packages":[{"name":"npm","source":"https://ubuntu.com/security/cve?package=npm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=npm","debian":"https://tracker.debian.org/pkg/npm","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-3918","published":"2021-11-13T09:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\njson-schema is vulnerable to Improperly Controlled Modification of Object\nPrototype Attributes ('Prototype Pollution')","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/kriszyp/json-schema/commit/22f146111f541d9737e832823699ad3528ca7741 (v0.4.0)","https://huntr.dev/bounties/bb6ccd63-f505-4e3a-b55f-cd2662c261a9","https://ubuntu.com/security/notices/USN-6103-1","https://www.cve.org/CVERecord?id=CVE-2021-3918"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=999765"],"patches":{"node-json-schema":["upstream: https://github.com/kriszyp/json-schema/commit/22f146111f541d9737e832823699ad3528ca7741"]},"tags":{},"packages":[{"name":"node-json-schema","source":"https://ubuntu.com/security/cve?package=node-json-schema","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-json-schema","debian":"https://tracker.debian.org/pkg/node-json-schema","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.2.3-1+deb10u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.2.3-1+deb10u1build0.20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.4.0+~7.0.9-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.4.0+~7.0.9-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.4.0+~7.0.9-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.4.0+~7.0.9-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6103-1"],"notices":[{"id":"USN-6103-1","title":"JSON Schema vulnerability","summary":"JSON Schema could be made to crash or run programs if it opened specially\ncrafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-05-24T11:08:39.734291","description":"It was discovered that JSON Schema incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to exploit\nJavaScript runtimes and cause a denial of service or execute arbitrary code.\n","is_hidden":false,"release_packages":{"focal":[{"name":"node-json-schema","version":"0.2.3-1+deb10u1build0.20.04.1","description":"A vocabulary that allows you to validate, annotate, and manipulate JSON files","is_source":true},{"name":"node-json-schema","version":"0.2.3-1+deb10u1build0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-json-schema","version_link":"https://launchpad.net/ubuntu/+source/node-json-schema/0.2.3-1+deb10u1build0.20.04.1","pocket":"security"}],"bionic":[{"name":"node-json-schema","version":"0.2.3-1+deb10u1build0.18.04.1","description":"A vocabulary that allows you to validate, annotate, and manipulate JSON files","is_source":true},{"name":"node-json-schema","version":"0.2.3-1+deb10u1build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-json-schema","version_link":"https://launchpad.net/ubuntu/+source/node-json-schema/0.2.3-1+deb10u1build0.18.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3918"]}]},{"id":"CVE-2021-41229","published":"2021-11-12T23:15:00","updated_at":"2025-08-18T17:16:54.367489+00:00","description":"\nBlueZ is a Bluetooth protocol stack for Linux. In affected versions a\nvulnerability exists in sdp_cstate_alloc_buf which allocates memory which\nwill always be hung in the singly linked list of cstates and will not be\nfreed. This will cause a memory leak over time. The data can be a very\nlarge object, which can be caused by an attacker continuously sending sdp\npackets and this may cause the service of the target device to crash.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"introduced in d939483328489fb835bb425d36f7c7c73d52c388 (v4.0)"}],"codename":null,"priority":"low","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/bluez/bluez/security/advisories/GHSA-3fqg-r8j5-f5xq","https://ubuntu.com/security/notices/USN-5155-1","https://www.cve.org/CVERecord?id=CVE-2021-41229"],"bugs":[""],"patches":{"bluez":["upstream: https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/?id=e79417ed7185b150a056d4eb3a1ab528b91d2fc0"]},"tags":{},"packages":[{"name":"bluez","source":"https://ubuntu.com/security/cve?package=bluez","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bluez","debian":"https://tracker.debian.org/pkg/bluez","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"5.48-0ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.53-0ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"5.56-0ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"5.60-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"5.62-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5155-1"],"notices":[{"id":"USN-5155-1","title":"BlueZ vulnerabilities","summary":"Several security issues were fixed in BlueZ.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-11-23T19:04:05.387846","description":"It was discovered that BlueZ incorrectly handled the Discoverable status\nwhen a device is powered down. This could result in devices being powered\nup discoverable, contrary to expectations. This issue only affected Ubuntu\n20.04 LTS, Ubuntu 21.04, and Ubuntu 21.10. (CVE-2021-3658)\n\nIt was discovered that BlueZ incorrectly handled certain memory operations.\nA remote attacker could possibly use this issue to cause BlueZ to consume\nresources, leading to a denial of service. (CVE-2021-41229)\n\nIt was discovered that the BlueZ gatt server incorrectly handled\ndisconnects. A remote attacker could possibly use this issue to cause\nBlueZ to crash, leading to a denial of service. (CVE-2021-43400)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"bluez","version":"5.56-0ubuntu4.3","description":"Bluetooth tools and daemons","is_source":true},{"name":"libbluetooth3","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"bluez-tests","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"bluez-obexd","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"bluetooth","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"bluez","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"bluez-hcidump","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"bluez-cups","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"},{"name":"libbluetooth-dev","version":"5.56-0ubuntu4.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.56-0ubuntu4.3","pocket":"security"}],"impish":[{"name":"bluez","version":"5.60-0ubuntu2.1","description":"Bluetooth tools and daemons","is_source":true},{"name":"libbluetooth3","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluez-tests","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluez-obexd","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluetooth","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluez","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluez-hcidump","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluez-meshd","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"bluez-cups","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"},{"name":"libbluetooth-dev","version":"5.60-0ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.60-0ubuntu2.1","pocket":"security"}],"focal":[{"name":"bluez","version":"5.53-0ubuntu3.4","description":"Bluetooth tools and daemons","is_source":true},{"name":"libbluetooth3","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"bluez-tests","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"bluez-obexd","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"bluetooth","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"bluez","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"bluez-hcidump","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"bluez-cups","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"},{"name":"libbluetooth-dev","version":"5.53-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.53-0ubuntu3.4","pocket":"security"}],"bionic":[{"name":"bluez","version":"5.48-0ubuntu3.6","description":"Bluetooth tools and daemons","is_source":true},{"name":"libbluetooth3","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"bluez-tests","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"bluez-obexd","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"bluetooth","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"bluez","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"bluez-hcidump","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"bluez-cups","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"},{"name":"libbluetooth-dev","version":"5.48-0ubuntu3.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3658","CVE-2021-41229","CVE-2021-43400"]}]},{"id":"CVE-2021-43332","published":"2021-11-12T21:15:00","updated_at":"2025-08-25T23:42:35.596878+00:00","description":"\nIn GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb\npage contains an encrypted version of the list admin password. This could\npotentially be cracked by a moderator via an offline brute-force attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://mail.python.org/archives/list/mailman-announce@python.org/message/I2X7PSFXIEPLM3UMKZMGOEO3UFYETGRL/","https://bugs.launchpad.net/mailman/+bug/1949403","https://ubuntu.com/security/notices/USN-5151-1","https://ubuntu.com/security/notices/USN-5151-2","https://www.cve.org/CVERecord?id=CVE-2021-43332"],"bugs":[""],"patches":{"mailman":[]},"tags":{},"packages":[{"name":"mailman","source":"https://ubuntu.com/security/cve?package=mailman","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mailman","debian":"https://tracker.debian.org/pkg/mailman","statuses":[{"release_codename":"bionic","status":"released","description":"1:2.1.26-1ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.1.20-1ubuntu0.6+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1:2.1.29-1ubuntu3.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5151-1","USN-5151-2"],"notices":[{"id":"USN-5151-1","title":"Mailman vulnerabilities","summary":"Several security issues were fixed in Mailman.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":["https://launchpad.net/bugs/1949401","https://launchpad.net/mailman/+bug/1949403"],"published":"2021-11-18T13:55:40.225929","description":"It was discovered that Mailman incorrectly handled certain URL.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2021-43331)\n\nIt was discovered that Mailman incorrectly handled certain inputs.\nAn attacker could possibly use this issue to expose sensitive information.\n(CVE-2021-43332)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"mailman","version":"1:2.1.26-1ubuntu0.5","description":"Web-based mailing list manager","is_source":true},{"name":"mailman","version":"1:2.1.26-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailman","version_link":"https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.5","pocket":"security"}],"xenial":[{"name":"mailman","version":"1:2.1.20-1ubuntu0.6+esm2","description":"Web-based mailing list manager","is_source":true},{"name":"mailman","version":"1:2.1.20-1ubuntu0.6+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailman","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-43332","CVE-2021-43331"]},{"id":"USN-5151-2","title":"Mailman vulnerabilities","summary":"Several security issues were fixed in Mailman.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-11-25T12:32:04.883089","description":"USN-5151-1 fixed several vulnerabilities in Mailman. This update provides\nthe corresponding update for Ubuntu 20.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Mailman incorrectly handled certain URL.\n An attacker could possibly use this issue to execute arbitrary code.\n (CVE-2021-43331)\n\n It was discovered that Mailman incorrectly handled certain inputs.\n An attacker could possibly use this issue to expose sensitive information.\n (CVE-2021-43332)\n","is_hidden":false,"release_packages":{"focal":[{"name":"mailman","version":"1:2.1.29-1ubuntu3.1+esm1","description":"Web-based mailing list manager","is_source":true},{"name":"mailman","version":"1:2.1.29-1ubuntu3.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailman","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-43332","CVE-2021-43331"]}]},{"id":"CVE-2021-43331","published":"2021-11-12T21:15:00","updated_at":"2025-08-25T23:42:35.596878+00:00","description":"\nIn GNU Mailman before 2.1.36, a crafted URL to the Cgi/options.py user\noptions page can execute arbitrary JavaScript for XSS.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://mail.python.org/archives/list/mailman-announce@python.org/message/I2X7PSFXIEPLM3UMKZMGOEO3UFYETGRL/","https://bugs.launchpad.net/mailman/+bug/1949401","https://ubuntu.com/security/notices/USN-5151-1","https://ubuntu.com/security/notices/USN-5151-2","https://www.cve.org/CVERecord?id=CVE-2021-43331"],"bugs":[""],"patches":{"mailman":[]},"tags":{},"packages":[{"name":"mailman","source":"https://ubuntu.com/security/cve?package=mailman","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mailman","debian":"https://tracker.debian.org/pkg/mailman","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.1.26-1ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.1.20-1ubuntu0.6+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1:2.1.29-1ubuntu3.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5151-1","USN-5151-2"],"notices":[{"id":"USN-5151-1","title":"Mailman vulnerabilities","summary":"Several security issues were fixed in Mailman.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":["https://launchpad.net/bugs/1949401","https://launchpad.net/mailman/+bug/1949403"],"published":"2021-11-18T13:55:40.225929","description":"It was discovered that Mailman incorrectly handled certain URL.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2021-43331)\n\nIt was discovered that Mailman incorrectly handled certain inputs.\nAn attacker could possibly use this issue to expose sensitive information.\n(CVE-2021-43332)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"mailman","version":"1:2.1.26-1ubuntu0.5","description":"Web-based mailing list manager","is_source":true},{"name":"mailman","version":"1:2.1.26-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailman","version_link":"https://launchpad.net/ubuntu/+source/mailman/1:2.1.26-1ubuntu0.5","pocket":"security"}],"xenial":[{"name":"mailman","version":"1:2.1.20-1ubuntu0.6+esm2","description":"Web-based mailing list manager","is_source":true},{"name":"mailman","version":"1:2.1.20-1ubuntu0.6+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailman","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-43332","CVE-2021-43331"]},{"id":"USN-5151-2","title":"Mailman vulnerabilities","summary":"Several security issues were fixed in Mailman.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-11-25T12:32:04.883089","description":"USN-5151-1 fixed several vulnerabilities in Mailman. This update provides\nthe corresponding update for Ubuntu 20.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Mailman incorrectly handled certain URL.\n An attacker could possibly use this issue to execute arbitrary code.\n (CVE-2021-43331)\n\n It was discovered that Mailman incorrectly handled certain inputs.\n An attacker could possibly use this issue to expose sensitive information.\n (CVE-2021-43332)\n","is_hidden":false,"release_packages":{"focal":[{"name":"mailman","version":"1:2.1.29-1ubuntu3.1+esm1","description":"Web-based mailing list manager","is_source":true},{"name":"mailman","version":"1:2.1.29-1ubuntu3.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mailman","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-43332","CVE-2021-43331"]}]},{"id":"CVE-2021-41259","published":"2021-11-12T18:15:00","updated_at":"2025-08-04T19:35:43.740836+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None.\nReason: This CVE ID has been rejected or withdrawn by its CVE Numbering\nAuthority. Notes: None.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/nim-lang/security/security/advisories/GHSA-3gg2-rw3q-qwgc","https://www.cve.org/CVERecord?id=CVE-2021-41259"],"bugs":[""],"patches":{"nim":[]},"tags":{},"packages":[{"name":"nim","source":"https://ubuntu.com/security/cve?package=nim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nim","debian":"https://tracker.debian.org/pkg/nim","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-3912","published":"2021-11-11T22:15:00","updated_at":"2025-08-25T23:40:06.788178+00:00","description":"\nOctoRPKI tries to load the entire contents of a repository in memory, and\nin the case of a GZIP bomb, unzip it in memory, making it possible to\ncreate a repository that makes OctoRPKI run out of memory (and thus crash).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/cloudflare/cfrpki/security/advisories/GHSA-g9wh-3vrx-r7hg","https://github.com/cloudflare/cfrpki/commit/32961e7a41cae67660dfee92095a1f6c2f86f943","https://www.cve.org/CVERecord?id=CVE-2021-3912"],"bugs":[""],"patches":{"cfrpki":[]},"tags":{},"packages":[{"name":"cfrpki","source":"https://ubuntu.com/security/cve?package=cfrpki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cfrpki","debian":"https://tracker.debian.org/pkg/cfrpki","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-3911","published":"2021-11-11T22:15:00","updated_at":"2025-08-25T23:40:06.788178+00:00","description":"\nIf the ROA that a repository returns contains too many bits for the IP\naddress then OctoRPKI will crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/cloudflare/cfrpki/security/advisories/GHSA-w6ww-fmfx-2x22","https://github.com/cloudflare/cfrpki/commit/7ca2435a078b0a9545ef7d9679a3b25bea141385","https://www.cve.org/CVERecord?id=CVE-2021-3911"],"bugs":[""],"patches":{"cfrpki":[]},"tags":{},"packages":[{"name":"cfrpki","source":"https://ubuntu.com/security/cve?package=cfrpki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cfrpki","debian":"https://tracker.debian.org/pkg/cfrpki","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.0","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":40640,"limit":20,"total_results":79316}