{"cves":[{"id":"CVE-2021-39134","published":"2021-08-31T17:15:00","updated_at":"2025-08-26T12:34:14.264154+00:00","description":"\n`@npmcli/arborist`, the library that calculates dependency trees and\nmanages the `node_modules` folder hierarchy for the npm command line\ninterface, aims to guarantee that package dependency contracts will be met,\nand the extraction of package contents will always be performed into the\nexpected folder. This is, in part, accomplished by resolving dependency\nspecifiers defined in `package.json` manifests for dependencies with a\nspecific name, and nesting folders to resolve conflicting dependencies.\nWhen multiple dependencies differ only in the case of their name,\nArborist's internal data structure saw them as separate items that could\ncoexist within the same level in the `node_modules` hierarchy. However, on\ncase-insensitive file systems (such as macOS and Windows), this is not the\ncase. Combined with a symlink dependency such as `file:/some/path`, this\nallowed an attacker to create a situation in which arbitrary contents could\nbe written to any location on the filesystem. For example, a package\n`pwn-a` could define a dependency in their `package.json` file such as\n`\"foo\": \"file:/some/path\"`. Another package, `pwn-b` could define a\ndependency such as `FOO: \"file:foo.tgz\"`. On case-insensitive file systems,\nif `pwn-a` was installed, and then `pwn-b` was installed afterwards, the\ncontents of `foo.tgz` would be written to `/some/path`, and any existing\ncontents of `/some/path` would be removed. Anyone using npm v7.20.6 or\nearlier on a case-insensitive filesystem is potentially affected. This is\npatched in @npmcli/arborist 2.8.2 which is included in npm v7.20.7 and\nabove.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/npm/arborist/security/advisories/GHSA-2h3h-q99f-3fhc","https://www.npmjs.com/package/@npmcli/arborist","https://www.cve.org/CVERecord?id=CVE-2021-39134"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993407"],"patches":{"npm":[]},"tags":{},"packages":[{"name":"npm","source":"https://ubuntu.com/security/cve?package=npm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=npm","debian":"https://tracker.debian.org/pkg/npm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"v7.20.7","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8.5.1~ds-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"9.2.0~ds1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"9.2.0~ds1-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"9.2.0~ds1-3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"9.2.0~ds1-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"9.2.0~ds1-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-37713","published":"2021-08-31T17:15:00","updated_at":"2025-08-25T23:39:02.449122+00:00","description":"\nThe npm package \"tar\" (aka node-tar) before versions 4.4.18, 5.0.10, and\n6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution\nvulnerability. node-tar aims to guarantee that any file whose location\nwould be outside of the extraction target directory is not extracted. This\nis, in part, accomplished by sanitizing absolute paths of entries within\nthe archive, skipping archive entries that contain `..` path portions, and\nresolving the sanitized paths against the extraction target directory. This\nlogic was insufficient on Windows systems when extracting tar files that\ncontained a path that was not an absolute path, but specified a drive\nletter different from the extraction target, such as `C:some\\path`. If the\ndrive letter does not match the extraction target, for example\n`D:\\extraction\\dir`, then the result of `path.resolve(extractionDirectory,\nentryPath)` would resolve against the current working directory on the `C:`\ndrive, rather than the extraction target directory. Additionally, a `..`\nportion of the path could occur immediately after the drive letter, such as\n`C:../foo`, and was not properly sanitized by the logic that checked for\n`..` within the normalized and split portions of the path. This only\naffects users of `node-tar` on Windows systems. These issues were addressed\nin releases 4.4.18, 5.0.10 and 6.1.9. The v3 branch of node-tar has been\ndeprecated and did not receive patches for these issues. If you are still\nusing a v3 release we recommend you update to a more recent version of\nnode-tar. There is no reasonable way to work around this issue without\nperforming the same path normalization procedures that node-tar now does.\nUsers are encouraged to upgrade to the latest patched versions of node-tar,\nrather than attempt to sanitize paths themselves.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/npm/node-tar/security/advisories/GHSA-5955-9wpr-37jh","https://www.npmjs.com/package/tar","https://www.cve.org/CVERecord?id=CVE-2021-37713"],"bugs":[""],"patches":{"node-tar":[]},"tags":{},"packages":[{"name":"node-tar","source":"https://ubuntu.com/security/cve?package=node-tar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-tar","debian":"https://tracker.debian.org/pkg/node-tar","statuses":[{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"debian: Only affects node-tar on Windows","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-37712","published":"2021-08-31T17:15:00","updated_at":"2025-07-11T07:47:51.315124+00:00","description":"\nThe npm package \"tar\" (aka node-tar) before versions 4.4.18, 5.0.10, and\n6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution\nvulnerability. node-tar aims to guarantee that any file whose location\nwould be modified by a symbolic link is not extracted. This is, in part,\nachieved by ensuring that extracted directories are not symlinks.\nAdditionally, in order to prevent unnecessary stat calls to determine\nwhether a given path is a directory, paths are cached when directories are\ncreated. This logic was insufficient when extracting tar files that\ncontained both a directory and a symlink with names containing unicode\nvalues that normalized to the same value. Additionally, on Windows systems,\nlong path portions would resolve to the same file system entities as their\n8.3 \"short path\" counterparts. A specially crafted tar archive could thus\ninclude a directory with one form of the path, followed by a symbolic link\nwith a different string that resolves to the same file system entity,\nfollowed by a file using the first form. By first creating a directory, and\nthen replacing that directory with a symlink that had a different apparent\nname that resolved to the same entry in the filesystem, it was thus\npossible to bypass node-tar symlink checks on directories, essentially\nallowing an untrusted tar file to symlink into an arbitrary location and\nsubsequently extracting arbitrary files into that location, thus allowing\narbitrary file creation and overwrite. These issues were addressed in\nreleases 4.4.18, 5.0.10 and 6.1.9. The v3 branch of node-tar has been\ndeprecated and did not receive patches for these issues. If you are still\nusing a v3 release we recommend you update to a more recent version of\nnode-tar. If this is not possible, a workaround is available in the\nreferenced GHSA-qq89-hq3f-393p.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/npm/node-tar/security/advisories/GHSA-qq89-hq3f-393p","https://www.npmjs.com/package/tar","https://www.cve.org/CVERecord?id=CVE-2021-37712"],"bugs":[""],"patches":{"node-tar":[]},"tags":{},"packages":[{"name":"node-tar","source":"https://ubuntu.com/security/cve?package=node-tar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-tar","debian":"https://tracker.debian.org/pkg/node-tar","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-37701","published":"2021-08-31T17:15:00","updated_at":"2025-08-26T12:33:58.869423+00:00","description":"\nThe npm package \"tar\" (aka node-tar) before versions 4.4.16, 5.0.8, and\n6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution\nvulnerability. node-tar aims to guarantee that any file whose location\nwould be modified by a symbolic link is not extracted. This is, in part,\nachieved by ensuring that extracted directories are not symlinks.\nAdditionally, in order to prevent unnecessary stat calls to determine\nwhether a given path is a directory, paths are cached when directories are\ncreated. This logic was insufficient when extracting tar files that\ncontained both a directory and a symlink with the same name as the\ndirectory, where the symlink and directory names in the archive entry used\nbackslashes as a path separator on posix systems. The cache checking logic\nused both `\\` and `/` characters as path separators, however `\\` is a valid\nfilename character on posix systems. By first creating a directory, and\nthen replacing that directory with a symlink, it was thus possible to\nbypass node-tar symlink checks on directories, essentially allowing an\nuntrusted tar file to symlink into an arbitrary location and subsequently\nextracting arbitrary files into that location, thus allowing arbitrary file\ncreation and overwrite. Additionally, a similar confusion could arise on\ncase-insensitive filesystems. If a tar archive contained a directory at\n`FOO`, followed by a symbolic link named `foo`, then on case-insensitive\nfile systems, the creation of the symbolic link would remove the directory\nfrom the filesystem, but _not_ from the internal directory cache, as it\nwould not be treated as a cache hit. A subsequent file entry within the\n`FOO` directory would then be placed in the target of the symbolic link,\nthinking that the directory had already been created. These issues were\naddressed in releases 4.4.16, 5.0.8 and 6.1.7. The v3 branch of node-tar\nhas been deprecated and did not receive patches for these issues. If you\nare still using a v3 release we recommend you update to a more recent\nversion of node-tar. If this is not possible, a workaround is available in\nthe referenced GHSA-9r2w-394v-53qc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/npm/node-tar/security/advisories/GHSA-9r2w-394v-53qc","https://www.npmjs.com/package/tar","https://www.cve.org/CVERecord?id=CVE-2021-37701"],"bugs":[""],"patches":{"node-tar":[]},"tags":{},"packages":[{"name":"node-tar","source":"https://ubuntu.com/security/cve?package=node-tar","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-tar","debian":"https://tracker.debian.org/pkg/node-tar","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.1.7+~cs11.3.10-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-39163","published":"2021-08-31T16:15:00","updated_at":"2025-08-26T12:34:14.264154+00:00","description":"\nMatrix is an ecosystem for open federated Instant Messaging and Voice over\nIP. In versions 1.41.0 and prior, unauthorised users can access the name,\navatar, topic and number of members of a room if they know the ID of the\nroom. This vulnerability is limited to homeservers where the vulnerable\nhomeserver is in the room and untrusted users are permitted to create\ngroups (communities). By default, only homeserver administrators can create\ngroups. However, homeserver administrators can already access this\ninformation in the database or using the admin API. As a result, only\nhomeservers where the configuration setting `enable_group_creation` has\nbeen set to `true` are impacted. Server administrators should upgrade to\n1.41.1 or higher to patch the vulnerability. There are two potential\nworkarounds. Server administrators can set `enable_group_creation` to\n`false` in their homeserver configuration (this is the default value) to\nprevent creation of groups by non-administrators. Administrators that are\nusing a reverse proxy could, with partial loss of group functionality,\nblock the endpoints `/_matrix/client/r0/groups/{group_id}/rooms` and\n`/_matrix/client/unstable/groups/{group_id}/rooms`.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://github.com/matrix-org/synapse/security/advisories/GHSA-jj53-8fmw-f2w2","https://github.com/matrix-org/synapse/commit/cb35df940a828bc40b96daed997b5ad4c7842fd3 (v1.41.1)","https://github.com/matrix-org/synapse/releases/tag/v1.41.1","https://github.com/matrix-org/synapse/commit/cb35df940a","https://www.cve.org/CVERecord?id=CVE-2021-39163"],"bugs":[""],"patches":{"matrix-synapse":[]},"tags":{},"packages":[{"name":"matrix-synapse","source":"https://ubuntu.com/security/cve?package=matrix-synapse","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=matrix-synapse","debian":"https://tracker.debian.org/pkg/matrix-synapse","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.41.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.64.0-3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.64.0-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.64.0-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.64.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40085","published":"2021-08-31T15:00:00","updated_at":"2025-08-18T17:16:48.796931+00:00","description":"\nAn issue was discovered in OpenStack Neutron before 16.4.1, 17.x before\n17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure\ndnsmasq via a crafted extra_dhcp_opts value.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This issue was fixed in (2:16.4.1-0ubuntu2) in focal-updates and\n(2:18.1.1-0ubuntu2) in hirsute-updates, and was later released\nto -security."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-6067-1","https://www.cve.org/CVERecord?id=CVE-2021-40085"],"bugs":["https://launchpad.net/bugs/1939733"],"patches":{"neutron":["upstream: https://opendev.org/openstack/neutron/commit/110fed07cb83deb3abd85073cb351066713b6384"]},"tags":{},"packages":[{"name":"neutron","source":"https://ubuntu.com/security/cve?package=neutron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neutron","debian":"https://tracker.debian.org/pkg/neutron","statuses":[{"release_codename":"jammy","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2:16.4.2-0ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.4.1, 17.2.1, 18.1.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:12.1.1-0ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2:18.1.1+git2021091315.0fa97ecceb-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6067-1"],"notices":[{"id":"USN-6067-1","title":"OpenStack Neutron vulnerabilities","summary":"Several security issues were fixed in OpenStack Neutron.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-05-10T11:30:08.483196","description":"David Sinquin discovered that OpenStack Neutron incorrectly handled the\ndefault Open vSwitch firewall rules. An attacker could possibly use this\nissue to impersonate the IPv6 addresses of other systems on the network.\nThis issue only affected Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2021-20267)\n\nJake Yip and Justin Mammarella discovered that OpenStack Neutron\nincorrectly handled the linuxbridge driver when ebtables-nft is being\nused. An attacker could possibly use this issue to impersonate the hardware\naddresss of other systems on the network. This issue only affected Ubuntu\n18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-38598)\n\nPavel Toporkov discovered that OpenStack Neutron incorrectly handled\nextra_dhcp_opts values. An attacker could possibly use this issue to\nreconfigure dnsmasq. This issue only affected Ubuntu 18.04 LTS, and Ubuntu\n20.04 LTS. (CVE-2021-40085)\n\nSlawek Kaplonski discovered that OpenStack Neutron incorrectly handled the\nroutes middleware. An attacker could possibly use this issue to cause the\nAPI worker to consume memory, leading to a denial of service. This issue\nonly affected Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2021-40797)\n\nIt was discovered that OpenStack Neutron incorrectly handled certain\nqueries. A remote authenticated user could possibly use this issue to cause\nresource consumption, leading to a denial of service. (CVE-2022-3277)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"neutron","version":"2:20.3.0-0ubuntu1.1","description":"OpenStack Virtual Network Service","is_source":true},{"name":"neutron-linuxbridge-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-metering-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-plugin-ml2","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-server","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-ovn-metadata-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"python3-neutron","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-l3-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-metadata-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-dhcp-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-sriov-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-openvswitch-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-common","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"},{"name":"neutron-macvtap-agent","version":"2:20.3.0-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:20.3.0-0ubuntu1.1","pocket":"security"}],"focal":[{"name":"neutron","version":"2:16.4.2-0ubuntu6.2","description":"OpenStack Virtual Network Service","is_source":true},{"name":"neutron-linuxbridge-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-metering-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-plugin-ml2","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-server","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-ovn-metadata-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"python3-neutron","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-l3-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-metadata-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-dhcp-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-sriov-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-openvswitch-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-common","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"},{"name":"neutron-macvtap-agent","version":"2:16.4.2-0ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:16.4.2-0ubuntu6.2","pocket":"security"}],"bionic":[{"name":"neutron","version":"2:12.1.1-0ubuntu8.1","description":"OpenStack Virtual Network Service","is_source":true},{"name":"neutron-plugin-linuxbridge-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-linuxbridge-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-metering-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-plugin-ml2","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-plugin-sriov-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-plugin-openvswitch-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-l3-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-metadata-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"python-neutron","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-dhcp-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-sriov-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-openvswitch-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-server","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-common","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"},{"name":"neutron-macvtap-agent","version":"2:12.1.1-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/neutron","version_link":"https://launchpad.net/ubuntu/+source/neutron/2:12.1.1-0ubuntu8.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-20267","CVE-2022-3277","CVE-2021-40085","CVE-2021-40797","CVE-2021-38598"]}]},{"id":"CVE-2021-3749","published":"2021-08-31T11:15:00","updated_at":"2025-07-11T07:47:51.315124+00:00","description":"\naxios is vulnerable to Inefficient Regular Expression Complexity","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31/","https://github.com/axios/axios/commit/5b457116e31db0e88fede6c428e969e87f290929","https://github.com/axios/axios/pull/3980","https://huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31","https://www.cve.org/CVERecord?id=CVE-2021-3749"],"bugs":[""],"patches":{"node-axios":[]},"tags":{},"packages":[{"name":"node-axios","source":"https://ubuntu.com/security/cve?package=node-axios","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-axios","debian":"https://tracker.debian.org/pkg/node-axios","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-40330","published":"2021-08-31T04:15:00","updated_at":"2025-08-25T23:41:12.801484+00:00","description":"\ngit_connect_git in connect.c in Git before 2.30.1 allows a repository path\nto contain a newline character, which may result in unexpected\ncross-protocol requests, as demonstrated by the\ngit://localhost:1234/%0d%0a%0d%0aGET%20/%20HTTP/1.1 substring.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/git/git/compare/v2.30.0...v2.30.1","https://ubuntu.com/security/notices/USN-5076-1","https://www.cve.org/CVERecord?id=CVE-2021-40330"],"bugs":[""],"patches":{"git":["upstream: https://github.com/git/git/commit/a02ea577174ab8ed18f847cf1693f213e0b9c473"]},"tags":{},"packages":[{"name":"git","source":"https://ubuntu.com/security/cve?package=git","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=git","debian":"https://tracker.debian.org/pkg/git","statuses":[{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.30.2-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.30.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.17.1-1ubuntu0.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:2.25.1-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.7.4-0ubuntu1.10+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5076-1"],"notices":[{"id":"USN-5076-1","title":"Git vulnerability","summary":"Git incorrectly handled certain repository paths.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-09-13T14:49:00.977893","description":"It was discovered that Git allowed newline characters in\ncertain repository paths. An attacker could potentially use this issue to perform\ncross-protocol requests.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"git","version":"1:2.17.1-1ubuntu0.9","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-all","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-cvs","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-daemon-run","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-daemon-sysvinit","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-doc","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-el","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-email","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-gui","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-man","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-mediawiki","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"git-svn","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"gitk","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"},{"name":"gitweb","version":"1:2.17.1-1ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.9","pocket":"security"}],"focal":[{"name":"git","version":"1:2.25.1-1ubuntu3.2","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-all","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-cvs","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-daemon-run","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-daemon-sysvinit","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-doc","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-el","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-email","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-gui","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-man","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-mediawiki","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"git-svn","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"gitk","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"},{"name":"gitweb","version":"1:2.25.1-1ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.2","pocket":"security"}],"xenial":[{"name":"git","version":"1:2.7.4-0ubuntu1.10+esm1","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-all","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-arch","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-core","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-cvs","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-daemon-run","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-daemon-sysvinit","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-doc","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-el","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-email","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-gui","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-man","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-mediawiki","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"git-svn","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"gitk","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"},{"name":"gitweb","version":"1:2.7.4-0ubuntu1.10+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-40330"]}]},{"id":"CVE-2021-3748","published":"2021-08-31T00:00:00","updated_at":"2025-08-25T23:38:53.876060+00:00","description":"\nA use-after-free vulnerability was found in the virtio-net device of QEMU.\nIt could occur when the descriptor's address belongs to the non direct\naccess region, due to num_buffers being set after the virtqueue elem has\nbeen unmapped. A malicious guest could use this flaw to crash QEMU,\nresulting in a denial of service condition, or potentially execute code on\nthe host with the privileges of the QEMU process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.nongnu.org/archive/html/qemu-devel/2021-09/msg00388.html","https://ubuntu.com/security/notices/USN-5307-1","https://www.cve.org/CVERecord?id=CVE-2021-3748"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1998514"],"patches":{"qemu":["upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=bedd7e93d01961fcb16a97ae45d93acf357e11f6"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"impish","status":"released","description":"1:6.0+dfsg-2expubuntu1.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1:6.2+dfsg-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.11+dfsg-1ubuntu7.39","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:4.2-3ubuntu6.21","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:6.2+dfsg-2ubuntu5","component":null,"pocket":"security"}]}],"notices_ids":["USN-5307-1"],"notices":[{"id":"USN-5307-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2022-02-28T13:03:07.827573","description":"Gaoning Pan discovered that QEMU incorrectly handled the floppy disk\nemulator. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2021-20196)\n\nGaoning Pan discovered that the QEMU vmxnet3 NIC emulator incorrectly\nhandled certain values. An attacker inside the guest could use this issue\nto cause QEMU to crash, resulting in a denial of service. (CVE-2021-20203)\n\nIt was discovered that the QEMU vhost-user GPU device contained several\nsecurity issues. An attacker inside the guest could use these issues to\ncause QEMU to crash, resulting in a denial of service, leak sensitive\ninformation, or possibly execute arbitrary code. This issue only affected\nUbuntu 21.10. (CVE-2021-3544, CVE-2021-3545, CVE-2021-3546)\n\nIt was discovered that QEMU incorrectly handled bulk transfers from SPICE\nclients. A remote attacker could use this issue to cause QEMU to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2021-3682)\n\nIt was discovered that the QEMU UAS device emulation incorrectly handled\ncertain stream numbers. An attacker inside the guest could use this issue\nto cause QEMU to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 21.10.\n(CVE-2021-3713)\n\nIt was discovered that the QEMU virtio-net device incorrectly handled\ncertain buffer addresses. An attacker inside the guest could use this issue\nto cause QEMU to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2021-3748)\n\nIt was discovered that the QEMU SCSI device emulation incorrectly handled\ncertain MODE SELECT commands. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2021-3930)\n\nIt was discovered that the QEMU ACPI logic incorrectly handled certain\nvalues. An attacker inside the guest could possibly use this issue to cause\nQEMU to crash, resulting in a denial of service. This issue only affected\nUbuntu 21.10. (CVE-2021-4158)\n\nJietao Xiao, Jinku Li, Wenbo Shen, and Nanzi Yang discovered that the QEMU\nvirtiofsd device incorrectly handled permissions when creating files. An\nattacker inside the guest could use this issue to create files inside the\ndirectory shared by virtiofs with unintended permissions, possibly allowing\nprivilege escalation. This issue only affected Ubuntu 21.10.\n(CVE-2022-0358)\n","is_hidden":false,"release_packages":{"impish":[{"name":"qemu","version":"1:6.0+dfsg-2expubuntu1.2","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-x86-microvm","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-common","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-user-static","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-misc","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-block-extra","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-s390x","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-user","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-guest-agent","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-utils","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-data","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-x86","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-sparc","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-gui","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-arm","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-ppc","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-mips","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:6.0+dfsg-2expubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:6.0+dfsg-2expubuntu1.2","pocket":"security"}],"focal":[{"name":"qemu","version":"1:4.2-3ubuntu6.21","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-x86-microvm","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-common","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-user-static","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-misc","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-block-extra","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-s390x","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-kvm","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-user","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-guest-agent","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-utils","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-data","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-x86","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-sparc","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-gui","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-arm","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-ppc","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-mips","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:4.2-3ubuntu6.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.21","pocket":"security"}],"bionic":[{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.39","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-common","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-user-static","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-kvm","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-user","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-utils","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.11+dfsg-1ubuntu7.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.39","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3544","CVE-2021-20196","CVE-2021-3713","CVE-2021-3748","CVE-2021-20203","CVE-2021-3546","CVE-2021-3930","CVE-2022-0358","CVE-2021-4158","CVE-2021-3545","CVE-2021-3682"]}]},{"id":"CVE-2021-3737","published":"2021-08-31T00:00:00","updated_at":"2025-08-25T23:38:48.475287+00:00","description":"\nA flaw was found in python. An improperly handled HTTP response in the HTTP\nclient code of python may allow a remote attacker, who controls the HTTP\nserver, to make the client script enter an infinite loop, consuming CPU\ntime. The highest threat from this vulnerability is to system availability.","ubuntu_description":"","notes":[{"author":"leosilva","note":"impish/devel is not affected, code supposed affected was patched already."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.python.org/issue44022","https://github.com/python/cpython/pull/25916","https://github.com/python/cpython/pull/26503","https://github.com/python/cpython/commit/60ba0b68470a584103e28958d91e93a6db37ec92 (v3.10.0b2)","https://github.com/python/cpython/commit/ea9327036680acc92d9f89eaf6f6a54d2f8d78d9 (v3.9.6)","https://github.com/python/cpython/commit/f396864ddfe914531b5856d7bf852808ebfc01ae (v3.8.11)","https://github.com/python/cpython/commit/078b146f062d212919d0ba25e34e658a8234aa63 (v3.7.11)","https://github.com/python/cpython/commit/f68d2d69f1da56c2aea1293ecf93ab69a6010ad7 (v3.6.14)","https://github.com/python/cpython/commit/98e5a7975d99b58d511f171816ecdfb13d5cca18 (v3.10.0b3)","https://github.com/python/cpython/commit/5df4abd6b033a5f1e48945c6988b45e35e76f647 (v3.9.6)","https://github.com/python/cpython/commit/0389426fa4af4dfc8b1d7f3f291932d928392d8b (3.8 branch)","https://github.com/python/cpython/commit/fee96422e6f0056561cf74fef2012cc066c9db86 (v3.7.11)","https://github.com/python/cpython/commit/1b6f4e5e13ebd1f957b47f7415b53d0869bdbac6 (v3.6.14","https://ubuntu.com/security/notices/USN-5083-1","https://ubuntu.com/security/notices/USN-5199-1","https://ubuntu.com/security/notices/USN-5200-1","https://ubuntu.com/security/notices/USN-5201-1","https://www.cve.org/CVERecord?id=CVE-2021-3737","https://ubuntu.com/security/notices/USN-6891-1"],"bugs":[""],"patches":{"python3.10":[],"python3.9":[],"python3.8":[],"python3.7":[],"python3.6":[],"python3.5":[],"python3.4":[]},"tags":{},"packages":[{"name":"python3.10","source":"https://ubuntu.com/security/cve?package=python3.10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.10","debian":"https://tracker.debian.org/pkg/python3.10","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.9","source":"https://ubuntu.com/security/cve?package=python3.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.9","debian":"https://tracker.debian.org/pkg/python3.9","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.9.5-3ubuntu0~20.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"3.9.5-3ubuntu0~21.04.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.8","source":"https://ubuntu.com/security/cve?package=python3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.8","debian":"https://tracker.debian.org/pkg/python3.8","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.8.0-3ubuntu1~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.8.10-0ubuntu1~20.04.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.7","source":"https://ubuntu.com/security/cve?package=python3.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.7","debian":"https://tracker.debian.org/pkg/python3.7","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.7.5-2ubuntu1~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.6","source":"https://ubuntu.com/security/cve?package=python3.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.6","debian":"https://tracker.debian.org/pkg/python3.6","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.6.9-1~18.04ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.4","source":"https://ubuntu.com/security/cve?package=python3.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.4","debian":"https://tracker.debian.org/pkg/python3.4","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.4.3-1ubuntu1~14.04.7+esm11","component":null,"pocket":"esm-infra"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.5","source":"https://ubuntu.com/security/cve?package=python3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.5","debian":"https://tracker.debian.org/pkg/python3.5","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.2-2ubuntu0~16.04.13+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5083-1","USN-5199-1","USN-5200-1","USN-5201-1","USN-6891-1"],"notices":[{"id":"USN-5083-1","title":"Python vulnerabilities","summary":"Several security issues were fixed in Python.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-09-16T17:27:34.033368","description":"It was discovered that Python incorrectly handled certain RFCs.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 16.04 ESM. (CVE-2021-3733)\n\nIt was discovered that Python incorrectly handled certain\nserver responses. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2021-3737)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"python3.4","version":"3.4.3-1ubuntu1~14.04.7+esm11","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.4","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.4","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.4-dev","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.4-minimal","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.4-stdlib","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.4-testsuite","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"python3.4","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"python3.4-dev","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"python3.4-doc","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"python3.4-examples","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"python3.4-minimal","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"},{"name":"python3.4-venv","version":"3.4.3-1ubuntu1~14.04.7+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-dev","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-minimal","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-stdlib","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-testsuite","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-dev","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-doc","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-examples","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-minimal","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-venv","version":"3.5.2-2ubuntu0~16.04.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-3733","CVE-2021-3737"]},{"id":"USN-5199-1","title":"Python vulnerabilities","summary":"\nPython could be made to crash if it receives specially crafted input from a malicious server.\n\n","instructions":"\nIn general, a standard system update will make all the necessary changes.\n\n","references":[],"published":"2021-12-17T14:53:00.335664","description":"\nIt was discovered that the urllib.request.AbstractBasicAuthHandler class \nin Python contains regex with a quadratic worst-case time complexity. \nSpecially crafted traffic from a malicious HTTP server could cause a regular \nexpression denial of service (ReDoS) condition for a client.\n(CVE-2021-3733)\n\nIt was discovered that the Python urllib http client could enter into an infinite \nloop when incorrectly handling certain server responses (100 Continue response). \nSpecially crafted traffic from a malicious HTTP server could cause a denial of \nservice (DoS) condition for a client.\n(CVE-2021-3737)\n\n","is_hidden":false,"release_packages":{"bionic":[{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1.6","description":"An interactive high-level object-oriented language","is_source":true},{"name":"libpython3.6-stdlib","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"python3.6-venv","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"python3.6-doc","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"libpython3.6-testsuite","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"python3.6-dev","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"python3.6-minimal","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"idle-python3.6","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"libpython3.6","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"libpython3.6-dev","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"python3.6-examples","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"},{"name":"libpython3.6-minimal","version":"3.6.9-1~18.04ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":"https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3737","CVE-2021-3733"]},{"id":"USN-5200-1","title":"Python vulnerabilities","summary":"\nPython could be made to crash if it receives specially crafted input from a malicious server.\n\n","instructions":"\nIn general, a standard system update will make all the necessary changes.\n\n","references":[],"published":"2021-12-17T14:59:29.220066","description":"\nIt was discovered that the urllib.request.AbstractBasicAuthHandler class \nin Python contains regex allowing for catastrophic backtracking. Specially \ncrafted traffic from a malicious HTTP server could cause a regular expression \ndenial of service (ReDoS) condition for a client.\n(CVE-2020-8492)\n\nIt was discovered that the urllib.request.AbstractBasicAuthHandler class \nin Python contains regex with a quadratic worst-case time complexity. \nSpecially crafted traffic from a malicious HTTP server could cause a regular \nexpression denial of service (ReDoS) condition for a client.\n(CVE-2021-3733)\n\nIt was discovered that the Python urllib http client could enter into an infinite \nloop when incorrectly handling certain server responses (100 Continue response). \nSpecially crafted traffic from a malicious HTTP server could cause a denial of \nservice (DoS) condition for a client.\n(CVE-2021-3737)\n\n","is_hidden":false,"release_packages":{"bionic":[{"name":"python3.7","version":"3.7.5-2ubuntu1~18.04.2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.8","version":"3.8.0-3ubuntu1~18.04.2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.7-doc","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.7-minimal","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"python3.7-minimal","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.7-dev","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.8-minimal","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"python3.8-venv","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"python3.7-dev","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.8-stdlib","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.7-testsuite","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.8-dev","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.7-stdlib","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"python3.7","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"python3.7-venv","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"python3.7-examples","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"idle-python3.7","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"},{"name":"idle-python3.8","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.8-testsuite","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"python3.8","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"python3.8-minimal","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"python3.8-examples","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"python3.8-dev","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.8","version":"3.8.0-3ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2","pocket":"security"},{"name":"libpython3.7","version":"3.7.5-2ubuntu1~18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":"https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3737","CVE-2020-8492","CVE-2021-3733"]},{"id":"USN-5201-1","title":"Python vulnerabilities","summary":"\nPython could be made to crash if it receives specially crafted input from a malicious server.\n\n","instructions":"\nIn general, a standard system update will make all the necessary changes.\n\n","references":[],"published":"2021-12-17T15:10:44.332712","description":"\nIt was discovered that the Python urllib http client could enter into an infinite \nloop when incorrectly handling certain server responses (100 Continue response). \nSpecially crafted traffic from a malicious HTTP server could cause a denial of \nservice (Dos) condition for a client.\n\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"python3.9","version":"3.9.5-3ubuntu0~21.04.1","description":"Interactive high-level object-oriented language (version 3.9)","is_source":true},{"name":"python3.9-dev","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"python3.9-examples","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"libpython3.9-minimal","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"python3.9-full","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"python3.9-venv","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"python3.9-doc","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"libpython3.9-dev","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"libpython3.9","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"python3.9-minimal","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"idle-python3.9","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"libpython3.9-testsuite","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"libpython3.9-stdlib","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"},{"name":"python3.9","version":"3.9.5-3ubuntu0~21.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~21.04.1","pocket":"security"}],"focal":[{"name":"python3.8","version":"3.8.10-0ubuntu1~20.04.2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1","description":"Interactive high-level object-oriented language (version 3.9)","is_source":true},{"name":"python3.8-full","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.9-venv","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"python3.9-doc","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"idle-python3.9","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"python3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"libpython3.8-minimal","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.8-venv","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.9-full","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"libpython3.9-dev","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"libpython3.8-dev","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"libpython3.8-stdlib","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"idle-python3.8","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"libpython3.8-testsuite","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"libpython3.9-testsuite","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"python3.8","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.8-doc","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.8-minimal","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.9-dev","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"python3.8-examples","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"python3.8-dev","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"libpython3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"python3.9-examples","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"libpython3.8","version":"3.8.10-0ubuntu1~20.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.2","pocket":"security"},{"name":"libpython3.9","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"},{"name":"libpython3.9-stdlib","version":"3.9.5-3ubuntu0~20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":"https://launchpad.net/ubuntu/+source/python3.9/3.9.5-3ubuntu0~20.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3737"]},{"id":"USN-6891-1","title":"Python vulnerabilities","summary":"Several security issues were fixed in Python.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-07-11T11:54:39.304153","description":"It was discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2015-20107)\n\nIt was discovered that Python incorrectly used regular expressions\nvulnerable to catastrophic backtracking. A remote attacker could possibly\nuse this issue to cause a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)\n\nIt was discovered that Python failed to initialize Expat’s hash salt. A\nremote attacker could possibly use this issue to cause hash collisions,\nleading to a denial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2018-14647)\n\nIt was discovered that Python incorrectly handled certain pickle files. An\nattacker could possibly use this issue to consume memory, leading to a\ndenial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2018-20406)\n\nIt was discovered that Python incorrectly validated the domain when\nhandling cookies. An attacker could possibly trick Python into sending\ncookies to the wrong domain. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2018-20852)\n\nJonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly\nhandled Unicode encoding during NFKC normalization. An attacker could\npossibly use this issue to obtain sensitive information. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2019-9636, CVE-2019-10160)\n\nIt was discovered that Python incorrectly parsed certain email addresses. A\nremote attacker could possibly use this issue to trick Python applications\ninto accepting email addresses that should be denied. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2019-16056)\n\nIt was discovered that the Python documentation XML-RPC server incorrectly\nhandled certain fields. A remote attacker could use this issue to execute a\ncross-site scripting (XSS) attack. This issue only affected Ubuntu 14.04\nLTS. (CVE-2019-16935)\n\nIt was discovered that Python documentation had a misleading information.\nA security issue could be possibly caused by wrong assumptions of this\ninformation. This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04\nLTS. (CVE-2019-17514)\n\nIt was discovered that Python incorrectly stripped certain characters from\nrequests. A remote attacker could use this issue to perform CRLF injection.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2019-18348)\n\nIt was discovered that Python incorrectly handled certain TAR archives.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2019-20907)\n\nColin Read and Nicolas Edet discovered that Python incorrectly handled\nparsing certain X509 certificates. An attacker could possibly use this\nissue to cause Python to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2019-5010)\n\nIt was discovered that incorrectly handled certain ZIP files. An attacker\ncould possibly use this issue to cause a denial of service. This issue only\naffected Ubuntu 14.04 LTS. (CVE-2019-9674)\n\nIt was discovered that Python incorrectly handled certain urls. A remote\nattacker could possibly use this issue to perform CRLF injection attacks.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2019-9740, CVE-2019-9947)\n\nSihoon Lee discovered that Python incorrectly handled the local_file:\nscheme. A remote attacker could possibly use this issue to bypass blocklist\nmeschanisms. This issue only affected Ubuntu 14.04 LTS. (CVE-2019-9948)\n\nIt was discovered that Python incorrectly handled certain IP values.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2020-14422)\n\nIt was discovered that Python incorrectly handled certain character\nsequences. A remote attacker could possibly use this issue to perform\nCRLF injection. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n18.04 LTS. (CVE-2020-26116)\n\nIt was discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code\nor cause a denial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2020-27619, CVE-2021-3177)\n\nIt was discovered that Python incorrectly handled certain HTTP requests.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2020-8492)\n\nIt was discovered that the Python stdlib ipaddress API incorrectly handled\noctal strings. A remote attacker could possibly use this issue to perform a\nwide variety of attacks, including bypassing certain access restrictions.\nThis issue only affected Ubuntu 18.04 LTS. (CVE-2021-29921)\n\nDavid Schwörer discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to expose sensitive information.\nThis issue only affected Ubuntu 18.04 LTS. (CVE-2021-3426)\n\nIt was discovered that Python incorrectly handled certain RFCs.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2021-3733)\n\nIt was discovered that Python incorrectly handled certain server\nresponses. An attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 14.04 LTS. (CVE-2021-3737)\n\nIt was discovered that Python incorrectly handled certain FTP requests.\nAn attacker could possibly use this issue to expose sensitive information.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2021-4189)\n\nIt was discovered that Python incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2022-0391)\n\nDevin Jeanpierre discovered that Python incorrectly handled sockets when\nthe multiprocessing module was being used. A local attacker could possibly\nuse this issue to execute arbitrary code and escalate privileges.\nThis issue only affected Ubuntu 22.04 LTS. (CVE-2022-42919)\n\nIt was discovered that Python incorrectly handled certain inputs. If a\nuser or an automated system were tricked into running a specially\ncrafted input, a remote attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 14.04 LTS,\nUbuntu 18.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-45061, CVE-2023-24329)\n\nIt was discovered that Python incorrectly handled certain scripts.\nAn attacker could possibly use this issue to execute arbitrary code\nor cause a crash. This issue only affected Ubuntu 14.04 LTS and\nUbuntu 18.04 LTS. (CVE-2022-48560)\n\nIt was discovered that Python incorrectly handled certain plist files.\nIf a user or an automated system were tricked into processing a specially\ncrafted plist file, an attacker could possibly use this issue to consume\nresources, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 18.04 LTS. (CVE-2022-48564)\n\nIt was discovered that Python did not properly handle XML entity\ndeclarations in plist files. An attacker could possibly use this\nvulnerability to perform an XML External Entity (XXE) injection,\nresulting in a denial of service or information disclosure. This issue\nonly affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS. (CVE-2022-48565)\n\nIt was discovered that Python did not properly provide constant-time\nprocessing for a crypto operation. An attacker could possibly use this\nissue to perform a timing attack and recover sensitive information. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2022-48566)\n\nIt was discovered that Python instances of ssl.SSLSocket were vulnerable\nto a bypass of the TLS handshake. An attacker could possibly use this\nissue to cause applications to treat unauthenticated received data before\nTLS handshake as authenticated data after TLS handshake. This issue only\naffected Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu\n22.04 LTS. (CVE-2023-40217)\n\nIt was discovered that Python incorrectly handled null bytes when\nnormalizing pathnames. An attacker could possibly use this issue to bypass\ncertain filename checks. This issue only affected Ubuntu 22.04 LTS.\n(CVE-2023-41105)\n\nIt was discovered that Python incorrectly handled privilege with certain\nparameters. An attacker could possibly use this issue to maintain the\noriginal processes' groups before starting the new process. This issue\nonly affected Ubuntu 23.10. (CVE-2023-6507)\n\nIt was discovered that Python incorrectly handled symlinks in temp files.\nAn attacker could possibly use this issue to modify the permissions of\nfiles. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS and Ubuntu 23.10. (CVE-2023-6597)\n\nIt was discovered that Python incorrectly handled certain crafted zip\nfiles. An attacker could possibly use this issue to crash the program,\nresulting in a denial of service. (CVE-2024-0450)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"idle-python3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"idle-python3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-dev","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-minimal","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-stdlib","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.6-testsuite","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-dev","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-minimal","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-stdlib","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.7-testsuite","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-dev","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-minimal","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-stdlib","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8-testsuite","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.6","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-dev","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-doc","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-examples","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-minimal","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.6-venv","version":"3.6.9-1~18.04ubuntu1.13+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.6","version_link":null,"pocket":"esm-infra"},{"name":"python3.7","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-dev","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-doc","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-examples","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-minimal","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.7-venv","version":"3.7.5-2ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.7","version_link":null,"pocket":"esm-apps"},{"name":"python3.8","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-dev","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-examples","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-minimal","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"},{"name":"python3.8-venv","version":"3.8.0-3ubuntu1~18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"python3.8","version":"3.8.10-0ubuntu1~20.04.10","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.8","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"idle-python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.8","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-dev","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-minimal","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-stdlib","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.8-testsuite","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"libpython3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-dev","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-stdlib","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.9-testsuite","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.8","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-dev","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-doc","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-examples","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-full","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-minimal","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.8-venv","version":"3.8.10-0ubuntu1~20.04.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.8","version_link":"https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.10","pocket":"security"},{"name":"python3.9","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-dev","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-doc","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-examples","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-full","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-minimal","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"},{"name":"python3.9-venv","version":"3.9.5-3ubuntu0~20.04.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.9","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"python3.10","version":"3.10.12-1~22.04.4","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.11","version":"3.11.0~rc1-1~22.04.1~esm1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.10","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"idle-python3.11","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.10","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-dev","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-minimal","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-stdlib","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.10-testsuite","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"libpython3.11","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-dev","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-minimal","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-stdlib","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"libpython3.11-testsuite","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.10","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-dev","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-doc","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-examples","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-full","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-minimal","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-nopie","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.10-venv","version":"3.10.12-1~22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.4","pocket":"security"},{"name":"python3.11","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-dev","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-doc","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-examples","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-full","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-minimal","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-nopie","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"},{"name":"python3.11-venv","version":"3.11.0~rc1-1~22.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":null,"pocket":"esm-apps"}],"mantic":[{"name":"python3.11","version":"3.11.6-3ubuntu0.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.12","version":"3.12.0-1ubuntu0.1","description":"Interactive high-level object-oriented language (version 3.12)","is_source":true},{"name":"idle-python3.11","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"idle-python3.12","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.11","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-dev","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-minimal","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-stdlib","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.11-testsuite","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"libpython3.12","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-dev","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-minimal","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-stdlib","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"libpython3.12-testsuite","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.11","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-dev","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-doc","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-examples","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-full","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-minimal","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-nopie","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.11-venv","version":"3.11.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.11","version_link":"https://launchpad.net/ubuntu/+source/python3.11/3.11.6-3ubuntu0.1","pocket":"security"},{"name":"python3.12","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-dev","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-doc","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-examples","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-full","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-minimal","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-nopie","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"},{"name":"python3.12-venv","version":"3.12.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.0-1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-dev","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-minimal","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-stdlib","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-testsuite","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-dev","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-doc","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-examples","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-minimal","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-venv","version":"3.5.2-2ubuntu0~16.04.4~14.04.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-dev","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-minimal","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-stdlib","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"libpython3.5-testsuite","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-dev","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-doc","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-examples","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-minimal","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"},{"name":"python3.5-venv","version":"3.5.2-2ubuntu0~16.04.13+esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-29921","CVE-2021-3733","CVE-2022-48560","CVE-2019-5010","CVE-2020-26116","CVE-2019-16056","CVE-2019-16935","CVE-2018-14647","CVE-2018-20406","CVE-2019-10160","CVE-2015-20107","CVE-2020-27619","CVE-2022-48564","CVE-2021-4189","CVE-2022-0391","CVE-2019-17514","CVE-2019-9740","CVE-2023-6507","CVE-2019-18348","CVE-2018-20852","CVE-2018-1061","CVE-2019-9674","CVE-2019-9636","CVE-2020-8492","CVE-2019-20907","CVE-2019-9947","CVE-2023-41105","CVE-2023-6597","CVE-2021-3737","CVE-2022-48566","CVE-2018-1060","CVE-2022-45061","CVE-2023-40217","CVE-2022-42919","CVE-2022-48565","CVE-2024-0450","CVE-2019-9948","CVE-2020-14422","CVE-2021-3426","CVE-2021-3177","CVE-2023-24329"]}]},{"id":"CVE-2021-36691","published":"2021-08-30T20:15:00","updated_at":"2025-07-15T15:00:08.706241+00:00","description":"\nlibjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc\njxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl,\nan attacker can trigger a denial of service.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nThis is just a DoS in out of memory conditions"},{"author":"mdeslaur","note":"as of 2025-04-14, there is no fix from upstream for this issue"},{"author":"ej7367","note":"As of 2025-07-15, there is no fix from upstream for this issue.\nMarking as ignored."}],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2021-36691"],"bugs":["https://github.com/libjxl/libjxl/issues/422","https://github.com/libjxl/libjxl/issues/762"],"patches":{"jpeg-xl":[]},"tags":{},"packages":[{"name":"jpeg-xl","source":"https://ubuntu.com/security/cve?package=jpeg-xl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jpeg-xl","debian":"https://tracker.debian.org/pkg/jpeg-xl","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-34434","published":"2021-08-30T20:15:00","updated_at":"2025-08-25T23:37:36.346432+00:00","description":"\nIn Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic\nsecurity plugin, if the ability for a client to make subscriptions on a\ntopic is revoked when a durable client is offline, then existing\nsubscriptions for that client are not revoked.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.eclipse.org/bugs/show_bug.cgi?id=575324","https://ubuntu.com/security/notices/USN-6492-1","https://www.cve.org/CVERecord?id=CVE-2021-34434"],"bugs":[""],"patches":{"mosquitto":[]},"tags":{},"packages":[{"name":"mosquitto","source":"https://ubuntu.com/security/cve?package=mosquitto","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mosquitto","debian":"https://tracker.debian.org/pkg/mosquitto","statuses":[{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.0.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.0.11-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2.0.11-1.2ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6492-1"],"notices":[{"id":"USN-6492-1","title":"Mosquitto vulnerabilities","summary":"Several security issues were fixed in Mosquitto.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-11-21T15:23:51.936272","description":"Kathrin Kleinhammer discovered that Mosquitto incorrectly handled certain\ninputs. If a user or an automated system were provided with a specially crafted\ninput, a remote attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-34431)\n\nZhanxiang Song discovered that Mosquitto incorrectly handled certain inputs. If\na user or an automated system were provided with a specially crafted input, a\nremote attacker could possibly use this issue to cause an authorisation bypass.\nThis issue only affected Ubuntu 22.04 LTS and Ubuntu 23.04. (CVE-2021-34434)\n\nZhanxiang Song, Bin Yuan, DeQing Zou, and Hai Jin discovered that Mosquitto\nincorrectly handled certain inputs. If a user or an automated system were\nprovided with a specially crafted input, a remote attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu 20.04\nLTS and Ubuntu 22.04 LTS. (CVE-2021-41039)\n\nZhengjie Du discovered that Mosquitto incorrectly handled certain inputs. If a\nuser or an automated system were provided with a specially crafted input file,\na remote attacker could possibly use this issue to cause a denial of service.\n(CVE-2023-0809)\n\nIt was discovered that Mosquitto incorrectly handled certain inputs. If a user\nor an automated system were provided with a specially crafted input, a remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2023-3592)\n\nMischa Bachmann discovered that Mosquitto incorrectly handled certain inputs.\nIf a user or an automated system were provided with a specially crafted input,\na remote attacker could possibly use this issue to cause a denial of service.\nThis issue was only fixed in Ubuntu 22.04 LTS and Ubuntu 23.04.\n(CVE-2023-28366)\n","is_hidden":false,"release_packages":{"focal":[{"name":"mosquitto","version":"1.6.9-1ubuntu0.1~esm1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquitto1","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquittopp-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"libmosquittopp1","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto-clients","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"},{"name":"mosquitto-dev","version":"1.6.9-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"mosquitto","version":"2.0.11-1ubuntu1.1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquitto1","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquittopp-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"libmosquittopp1","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto-clients","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"},{"name":"mosquitto-dev","version":"2.0.11-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1ubuntu1.1","pocket":"security"}],"lunar":[{"name":"mosquitto","version":"2.0.11-1.2ubuntu0.1","description":"MQTT version 3.1/3.1.1 compatible message broker","is_source":true},{"name":"libmosquitto-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquitto1","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquittopp-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"libmosquittopp1","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto-clients","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"},{"name":"mosquitto-dev","version":"2.0.11-1.2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mosquitto","version_link":"https://launchpad.net/ubuntu/+source/mosquitto/2.0.11-1.2ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2023-0809","CVE-2021-34434","CVE-2023-28366","CVE-2021-41039","CVE-2023-3592","CVE-2021-34431"]}]},{"id":"CVE-2021-36370","published":"2021-08-30T19:15:00","updated_at":"2025-08-25T23:38:35.336084+00:00","description":"\nAn issue was discovered in Midnight Commander through 4.8.26. When\nestablishing an SFTP connection, the fingerprint of the server is neither\nchecked nor displayed. As a result, a user connects to the server without\nthe ability to verify its authenticity.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/MidnightCommander/mc/commit/9235d3c232d13ad7f973346077c9cf2eaa77dc5f","https://github.com/MidnightCommander/mc/blob/master/src/vfs/sftpfs/connection.c","https://github.com/MidnightCommander/mc/blob/5c1d3c55dd15356ec7d079084d904b7b0fd58d3e/src/vfs/sftpfs/connection.c#L484","https://sourceforge.net/projects/mcwin32/files/","https://midnight-commander.org/","https://ubuntu.com/security/notices/USN-5160-1","https://www.cve.org/CVERecord?id=CVE-2021-36370"],"bugs":[""],"patches":{"mc":["upstream: https://github.com/MidnightCommander/mc/commit/9235d3c232d13ad7f973346077c9cf2eaa77dc5f"]},"tags":{},"packages":[{"name":"mc","source":"https://ubuntu.com/security/cve?package=mc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mc","debian":"https://tracker.debian.org/pkg/mc","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3:4.8.11-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3:4.8.19-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"3:4.8.24-2ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"3:4.8.15-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3:4.8.27-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3:4.8.27-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5160-1"],"notices":[{"id":"USN-5160-1","title":"Midnight Commander vulnerability","summary":"Midnight Commander could be made to access a spoofed server instance.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-08-09T11:44:21.604419","description":"It was discovered that Midnight Commander would not check server fingerprints\nwhen establishing an SFTP connection. If a remote attacker were able to intercept\ncommunications this flaw could be exploited to impersonate the SFTP server.\n","is_hidden":false,"release_packages":{"focal":[{"name":"mc","version":"3:4.8.24-2ubuntu1+esm1","description":"Midnight Commander - a powerful file manager","is_source":true},{"name":"mc-data","version":"3:4.8.24-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-apps"},{"name":"mc","version":"3:4.8.24-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"mc","version":"3:4.8.11-1ubuntu0.1~esm1","description":"Midnight Commander - a powerful file manager","is_source":true},{"name":"mc-data","version":"3:4.8.11-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-infra"},{"name":"mc","version":"3:4.8.11-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-infra"}],"bionic":[{"name":"mc","version":"3:4.8.19-1ubuntu0.1~esm1","description":"Midnight Commander - a powerful file manager","is_source":true},{"name":"mc-data","version":"3:4.8.19-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-apps"},{"name":"mc","version":"3:4.8.19-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"mc","version":"3:4.8.15-2ubuntu0.1~esm1","description":"Midnight Commander - a powerful file manager","is_source":true},{"name":"mc-data","version":"3:4.8.15-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-apps"},{"name":"mc","version":"3:4.8.15-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mc","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-36370"]}]},{"id":"CVE-2021-27020","published":"2021-08-30T18:15:00","updated_at":"2025-08-26T12:29:50.258472+00:00","description":"\nPuppet Enterprise presented a security risk by not sanitizing user input\nwhen doing a CSV export.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://puppet.com/security/cve/CVE-2021-27020","https://www.cve.org/CVERecord?id=CVE-2021-27020"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-27019","published":"2021-08-30T18:15:00","updated_at":"2025-07-11T07:46:38.192998+00:00","description":"\nPuppetDB logging included potentially sensitive system information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://puppet.com/security/cve/CVE-2021-27019","https://www.cve.org/CVERecord?id=CVE-2021-27019"],"bugs":[""],"patches":{"puppetdb":[]},"tags":{},"packages":[{"name":"puppetdb","source":"https://ubuntu.com/security/cve?package=puppetdb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppetdb","debian":"https://tracker.debian.org/pkg/puppetdb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-27018","published":"2021-08-30T18:15:00","updated_at":"2025-08-26T12:29:50.258472+00:00","description":"\nThe mechanism which performs certificate validation was discovered to have\na flaw that resulted in certificates signed by an internal certificate\nauthority to not be properly validated. This issue only affects clients\nthat are configured to utilize Tenable.sc as the vulnerability data source.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://puppet.com/security/cve/CVE-2021-27018","https://www.cve.org/CVERecord?id=CVE-2021-27018"],"bugs":[""],"patches":{"puppet":[]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35635","published":"2021-08-30T18:15:00","updated_at":"2025-08-26T12:24:57.391697+00:00","description":"\nA code execution vulnerability exists in the Nef polygon-parsing\nfunctionality of CGAL libcgal CGAL-5.1.1 in Nef_S2/SNC_io_parser.h\nSNC_io_parser::read_sface() store_sm_boundary_item() Sloop_of OOB read. A\nspecially crafted malformed file can lead to an out-of-bounds read and type\nconfusion, which could lead to code execution. An attacker can provide\nmalicious input to trigger this vulnerability.","ubuntu_description":"","notes":[{"author":"pfsmorigo","note":"possible regression introduced by fix, see GH issue 5514"}],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225","https://github.com/CGAL/cgal/pull/5371","https://github.com/CGAL/cgal/issues/5514","https://www.cve.org/CVERecord?id=CVE-2020-35635"],"bugs":[""],"patches":{"cgal":[]},"tags":{},"packages":[{"name":"cgal","source":"https://ubuntu.com/security/cve?package=cgal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cgal","debian":"https://tracker.debian.org/pkg/cgal","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35634","published":"2021-08-30T18:15:00","updated_at":"2025-08-26T12:24:57.391697+00:00","description":"\nA code execution vulnerability exists in the Nef polygon-parsing\nfunctionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists\nin Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface()\nsfh->boundary_entry_objects Sloop_of. A specially crafted malformed file\ncan lead to an out-of-bounds read and type confusion, which could lead to\ncode execution. An attacker can provide malicious input to trigger this\nvulnerability.","ubuntu_description":"","notes":[{"author":"pfsmorigo","note":"possible regression introduced by fix, see GH issue 5514"}],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225","https://github.com/CGAL/cgal/pull/5371","https://github.com/CGAL/cgal/issues/5514","https://www.cve.org/CVERecord?id=CVE-2020-35634"],"bugs":[""],"patches":{"cgal":[]},"tags":{},"packages":[{"name":"cgal","source":"https://ubuntu.com/security/cve?package=cgal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cgal","debian":"https://tracker.debian.org/pkg/cgal","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-35633","published":"2021-08-30T18:15:00","updated_at":"2025-08-26T12:24:57.391697+00:00","description":"\nA code execution vulnerability exists in the Nef polygon-parsing\nfunctionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists\nin Nef_S2/SNC_io_parser.h SNC_io_parser::read_sface()\nstore_sm_boundary_item() Edge_of.A specially crafted malformed file can\nlead to an out-of-bounds read and type confusion, which could lead to code\nexecution. An attacker can provide malicious input to trigger this\nvulnerability.","ubuntu_description":"","notes":[{"author":"pfsmorigo","note":"possible regression introduced by fix, see GH issue 5514"}],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1225","https://github.com/CGAL/cgal/pull/5371","https://github.com/CGAL/cgal/issues/5514","https://www.cve.org/CVERecord?id=CVE-2020-35633"],"bugs":[""],"patches":{"cgal":[]},"tags":{},"packages":[{"name":"cgal","source":"https://ubuntu.com/security/cve?package=cgal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cgal","debian":"https://tracker.debian.org/pkg/cgal","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"5.2-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-39272","published":"2021-08-30T06:15:00","updated_at":"2025-08-26T12:34:14.264154+00:00","description":"\nFetchmail before 6.4.22 fails to enforce STARTTLS session encryption in\nsome circumstances, such as a certain situation with IMAP and PREAUTH.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"when backporting, upstream is asking to make sure we update\ndocumentation covering the fixes as well"},{"author":"mdeslaur","note":"only an issue with IMAP PREAUTH sessions and STARTTLS. It is\nrecommended to switch to implicit TLS"}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.fetchmail.info/fetchmail-SA-2021-02.txt","https://www.openwall.com/lists/oss-security/2021/08/27/3","https://nostarttls.secvuln.info/","https://www.cve.org/CVERecord?id=CVE-2021-39272"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1190069","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=993163"],"patches":{"fetchmail":[]},"tags":{},"packages":[{"name":"fetchmail","source":"https://ubuntu.com/security/cve?package=fetchmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fetchmail","debian":"https://tracker.debian.org/pkg/fetchmail","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.4.22","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.4.27-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.4.32-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":41360,"limit":20,"total_results":79316}