{"cves":[{"id":"CVE-2021-22880","published":"2021-02-11T18:15:00","updated_at":"2025-07-11T07:46:16.233823+00:00","description":"\nThe PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5\nsuffers from a regular expression denial of service (REDoS) vulnerability.\nCarefully crafted input can cause the input validation in the `money` type\nof the PostgreSQL adapter in Active Record to spend too much time in a\nregular expression, resulting in the potential for a DoS attack. This only\nimpacts Rails applications that are using PostgreSQL along with money type\ncolumns that take user input.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://discuss.rubyonrails.org/t/cve-2021-22880-possible-dos-vulnerability-in-active-record-postgresql-adapter/77129","https://hackerone.com/reports/1023899","https://www.cve.org/CVERecord?id=CVE-2021-22880"],"bugs":[""],"patches":{"rails":[],"ruby-rails-3.2":[],"ruby-actionpack-3.2":[],"ruby-activesupport-3.2":[],"ruby-activerecord-3.2":[],"ruby-activemodel-3.2":[],"rails-4.0":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"rails-4.0","source":"https://ubuntu.com/security/cve?package=rails-4.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rails-4.0","debian":"https://tracker.debian.org/pkg/rails-4.0","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-actionpack-3.2","source":"https://ubuntu.com/security/cve?package=ruby-actionpack-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-actionpack-3.2","debian":"https://tracker.debian.org/pkg/ruby-actionpack-3.2","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activemodel-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activemodel-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-activemodel-3.2","debian":"https://tracker.debian.org/pkg/ruby-activemodel-3.2","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activerecord-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activerecord-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-activerecord-3.2","debian":"https://tracker.debian.org/pkg/ruby-activerecord-3.2","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activesupport-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activesupport-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-activesupport-3.2","debian":"https://tracker.debian.org/pkg/ruby-activesupport-3.2","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-rails-3.2","source":"https://ubuntu.com/security/cve?package=ruby-rails-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-rails-3.2","debian":"https://tracker.debian.org/pkg/ruby-rails-3.2","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-21299","published":"2021-02-11T18:15:00","updated_at":"2025-07-11T07:46:09.966636+00:00","description":"\nhyper is an open-source HTTP library for Rust (crates.io). In hyper from\nversion 0.12.0 and before versions 0.13.10 and 0.14.3 there is a\nvulnerability that can enable a request smuggling attack. The HTTP server\ncode had a flaw that incorrectly understands some requests with multiple\ntransfer-encoding headers to have a chunked payload, when it should have\nbeen rejected as illegal. This combined with an upstream HTTP proxy that\nunderstands the request payload boundary differently can result in \"request\nsmuggling\" or \"desync attacks\". To determine if vulnerable, all these\nthings must be true: 1) Using hyper as an HTTP server (the client is not\naffected), 2) Using HTTP/1.1 (HTTP/2 does not use transfer-encoding), 3)\nUsing a vulnerable HTTP proxy upstream to hyper. If an upstream proxy\ncorrectly rejects the illegal transfer-encoding headers, the desync attack\ncannot succeed. If there is no proxy upstream of hyper, hyper cannot start\nthe desync attack, as the client will repair the headers before forwarding.\nThis is fixed in versions 0.14.3 and 0.13.10. As a workaround one can take\nthe following options: 1) Reject requests that contain a\n`transfer-encoding` header, 2) Ensure any upstream proxy handles\n`transfer-encoding` correctly.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/hyperium/hyper/security/advisories/GHSA-6hfq-h8hq-87mf","https://rustsec.org/advisories/RUSTSEC-2021-0020.html","https://crates.io/crates/hyper","https://github.com/hyperium/hyper/commit/8f93123efef5c1361086688fe4f34c83c89cec02","https://portswigger.net/research/http-desync-attacks-request-smuggling-reborn","https://www.cve.org/CVERecord?id=CVE-2021-21299"],"bugs":[""],"patches":{"rust-hyper":[]},"tags":{},"packages":[{"name":"rust-hyper","source":"https://ubuntu.com/security/cve?package=rust-hyper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-hyper","debian":"https://tracker.debian.org/pkg/rust-hyper","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-20188","published":"2021-02-11T18:15:00","updated_at":"2025-07-11T07:46:03.824279+00:00","description":"\nA flaw was found in podman before 1.7.0. File permissions for non-root\nusers running in a privileged container are not correctly checked. This\nflaw can be abused by a low-privileged user inside the container to access\nany other file in the container, even if owned by the root user inside the\ncontainer. It does not allow to directly escape the container, though being\na privileged container means that a lot of security features are disabled\nwhen running the container. The highest threat from this vulnerability is\nto data confidentiality and integrity as well as system availability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1915734","https://github.com/containers/podman/commit/2c7b579fe7328dc6db48bdaf60d0ddd9136b1e24","https://github.com/containers/podman/commit/c8bd4746151e6ae37d49c4688f2f64e03db429fc","https://www.cve.org/CVERecord?id=CVE-2021-20188"],"bugs":[""],"patches":{"libpod":[]},"tags":{},"packages":[{"name":"libpod","source":"https://ubuntu.com/security/cve?package=libpod","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpod","debian":"https://tracker.debian.org/pkg/libpod","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-8031","published":"2021-02-11T15:15:00","updated_at":"2025-07-11T07:45:54.037247+00:00","description":"\nA Improper Neutralization of Input During Web Page Generation ('Cross-site\nScripting') vulnerability in Open Build Service allows remote attackers to\nstore JS code in markdown that is not properly escaped, impacting\nconfidentiality and integrity. This issue affects: Open Build Service\nversions prior to 2.10.8.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.suse.com/show_bug.cgi?id=1178880","https://www.cve.org/CVERecord?id=CVE-2020-8031"],"bugs":[""],"patches":{"open-build-service":[]},"tags":{},"packages":[{"name":"open-build-service","source":"https://ubuntu.com/security/cve?package=open-build-service","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=open-build-service","debian":"https://tracker.debian.org/pkg/open-build-service","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-23334","published":"2021-02-11T12:15:00","updated_at":"2025-08-04T19:35:28.917495+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none.\nReason: This candidate was withdrawn by its CNA. Further investigation\nshowed that it was not a security issue. Notes: none","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/browserify/static-eval/blob/master/index.js%23L180","https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1071860","https://snyk.io/vuln/SNYK-JS-STATICEVAL-1056765","https://www.cve.org/CVERecord?id=CVE-2021-23334"],"bugs":[""],"patches":{"node-static-eval":[]},"tags":{},"packages":[{"name":"node-static-eval","source":"https://ubuntu.com/security/cve?package=node-static-eval","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-static-eval","debian":"https://tracker.debian.org/pkg/node-static-eval","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-20335","published":"2021-02-11T10:15:00","updated_at":"2025-08-26T12:27:43.663982+00:00","description":"\nFor MongoDB Ops Manager versions prior to and including 4.2.24 with\nmultiple OM application servers, that have SSL turned on for their MongoDB\nprocesses, the upgrade to MongoDB Ops Manager versions prior to and\nincluding 4.4.12 triggers a bug where Automation thinks SSL is being turned\noff, and can disable SSL temporarily for members of the cluster. This issue\nis temporary and eventually corrects itself after MongoDB Ops Manager\ninstances have finished upgrading to MongoDB Ops Manager 4.4. In addition,\ncustomers must be running with clientCertificateMode=OPTIONAL /\nallowConnectionsWithoutCertificates=true to be impacted*.* Customers\nupgrading from Ops Manager 4.2.X to 4.2.24 and finally to Ops Manager\n4.4.13+ are unaffected by this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://docs-opsmanager-staging.mongodb.com/docsworker-xlarge/DOCSP-14164/release-notes/application.html","https://www.cve.org/CVERecord?id=CVE-2021-20335"],"bugs":[""],"patches":{"mongodb":[]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"affects mongo-opsmanager not mongodb","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.25, 4.4.13","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"affects mongo-opsmanager not mongodb","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"affects mongo-opsmanager not mongodb","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"affects mongo-opsmanager not mongodb","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-28596","published":"2021-02-10T22:15:00","updated_at":"2025-07-11T07:45:05.149852+00:00","description":"\nA stack-based buffer overflow vulnerability exists in the\nObjparser::objparse() functionality of Prusa Research PrusaSlicer 2.2.0 and\nMaster (commit 4b040b856). A specially crafted obj file can lead to code\nexecution. An attacker can provide a malicious file to trigger this\nvulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1220","https://www.cve.org/CVERecord?id=CVE-2020-28596"],"bugs":[""],"patches":{"slic3r-prusa":[]},"tags":{},"packages":[{"name":"slic3r-prusa","source":"https://ubuntu.com/security/cve?package=slic3r-prusa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=slic3r-prusa","debian":"https://tracker.debian.org/pkg/slic3r-prusa","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-28595","published":"2021-02-10T22:15:00","updated_at":"2025-07-11T07:45:05.149852+00:00","description":"\nAn out-of-bounds write vulnerability exists in the Obj.cpp load_obj()\nfunctionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit\n4b040b856). A specially crafted obj file can lead to code execution. An\nattacker can provide a malicious file to trigger this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1219","https://www.cve.org/CVERecord?id=CVE-2020-28595"],"bugs":[""],"patches":{"slic3r-prusa":[]},"tags":{},"packages":[{"name":"slic3r-prusa","source":"https://ubuntu.com/security/cve?package=slic3r-prusa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=slic3r-prusa","debian":"https://tracker.debian.org/pkg/slic3r-prusa","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-13578","published":"2021-02-10T20:15:00","updated_at":"2025-07-11T07:43:18.808801+00:00","description":"\nA denial-of-service vulnerability exists in the WS-Security plugin\nfunctionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request\ncan lead to denial of service. An attacker can send an HTTP request to\ntrigger this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1189","https://www.cve.org/CVERecord?id=CVE-2020-13578"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=983596"],"patches":{"gsoap":[]},"tags":{},"packages":[{"name":"gsoap","source":"https://ubuntu.com/security/cve?package=gsoap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gsoap","debian":"https://tracker.debian.org/pkg/gsoap","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-13575","published":"2021-02-10T20:15:00","updated_at":"2025-08-26T12:19:15.310212+00:00","description":"\nA denial-of-service vulnerability exists in the WS-Addressing plugin\nfunctionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request\ncan lead to denial of service. An attacker can send an HTTP request to\ntrigger this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1186","https://www.cve.org/CVERecord?id=CVE-2020-13575"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=983596"],"patches":{"gsoap":[]},"tags":{},"packages":[{"name":"gsoap","source":"https://ubuntu.com/security/cve?package=gsoap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gsoap","debian":"https://tracker.debian.org/pkg/gsoap","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8.104","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-13574","published":"2021-02-10T20:15:00","updated_at":"2025-08-26T12:19:15.310212+00:00","description":"\nA denial-of-service vulnerability exists in the WS-Security plugin\nfunctionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request\ncan lead to denial of service. An attacker can send an HTTP request to\ntrigger this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1185","https://www.cve.org/CVERecord?id=CVE-2020-13574"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=983596"],"patches":{"gsoap":[]},"tags":{},"packages":[{"name":"gsoap","source":"https://ubuntu.com/security/cve?package=gsoap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gsoap","debian":"https://tracker.debian.org/pkg/gsoap","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8.104-3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.8.117-2build1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-13565","published":"2021-02-10T20:15:00","updated_at":"2025-08-26T12:19:15.310212+00:00","description":"\nAn open redirect vulnerability exists in the return_page redirection\nfunctionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development\nversion 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A\nspecially crafted HTTP request can redirect users to an arbitrary URL. An\nattacker can provide a crafted URL to trigger this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://talosintelligence.com/vulnerability_reports/TALOS-2020-1178","https://www.cve.org/CVERecord?id=CVE-2020-13565"],"bugs":[""],"patches":{"phpgacl":[]},"tags":{},"packages":[{"name":"phpgacl","source":"https://ubuntu.com/security/cve?package=phpgacl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpgacl","debian":"https://tracker.debian.org/pkg/phpgacl","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-7021","published":"2021-02-10T19:15:00","updated_at":"2025-08-26T12:26:26.945172+00:00","description":"\nElasticsearch versions before 7.10.0 and 6.8.14 have an information\ndisclosure issue when audit logging and the emit_request_body option is\nenabled. The Elasticsearch audit log could contain sensitive information\nsuch as password hashes or authentication tokens. This could allow an\nElasticsearch administrator to view these details.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://discuss.elastic.co/t/elastic-stack-7-11-0-and-6-8-14-security-update/263915","https://www.cve.org/CVERecord?id=CVE-2020-7021"],"bugs":[""],"patches":{"elasticsearch":[]},"tags":{},"packages":[{"name":"elasticsearch","source":"https://ubuntu.com/security/cve?package=elasticsearch","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=elasticsearch","debian":"https://tracker.debian.org/pkg/elasticsearch","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-27135","published":"2021-02-10T16:15:00","updated_at":"2025-08-25T23:34:07.121352+00:00","description":"\nxterm before Patch #366 allows remote attackers to execute arbitrary code\nor cause a denial of service (segmentation fault) via a crafted UTF-8\ncombining character sequence.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2021/02/09/7","https://www.openwall.com/lists/oss-security/2021/02/09/9","https://www.openwall.com/lists/oss-security/2021/02/10/7","https://ubuntu.com/security/notices/USN-4746-1","https://www.cve.org/CVERecord?id=CVE-2021-27135"],"bugs":[""],"patches":{"xterm":["upstream: https://github.com/ThomasDickey/xterm-snapshots/commit/82ba55b8f994ab30ff561a347b82ea340ba7075c","upstream: https://github.com/ThomasDickey/xterm-snapshots/commit/f80e543c6dee5ecfe54c58d351fe418ce5f1959b"]},"tags":{},"packages":[{"name":"xterm","source":"https://ubuntu.com/security/cve?package=xterm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xterm","debian":"https://tracker.debian.org/pkg/xterm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"330-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"353-1ubuntu1.20.04.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"353-1ubuntu1.20.10.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"322-1ubuntu1.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4746-1"],"notices":[{"id":"USN-4746-1","title":"xterm vulnerability","summary":"xterm could be made to crash or run programs if it handled specially\ncrafted character sequences.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-02-24T13:51:11.922769","description":"Tavis Ormandy discovered that xterm incorrectly handled certain character\nsequences. A remote attacker could use this issue to cause xterm to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"xterm","version":"330-1ubuntu2.2","description":"X terminal emulator","is_source":true},{"name":"xterm","version":"330-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xterm","version_link":"https://launchpad.net/ubuntu/+source/xterm/330-1ubuntu2.2","pocket":"security"}],"focal":[{"name":"xterm","version":"353-1ubuntu1.20.04.2","description":"X terminal emulator","is_source":true},{"name":"xterm","version":"353-1ubuntu1.20.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xterm","version_link":"https://launchpad.net/ubuntu/+source/xterm/353-1ubuntu1.20.04.2","pocket":"security"}],"groovy":[{"name":"xterm","version":"353-1ubuntu1.20.10.2","description":"X terminal emulator","is_source":true},{"name":"xterm","version":"353-1ubuntu1.20.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xterm","version_link":"https://launchpad.net/ubuntu/+source/xterm/353-1ubuntu1.20.10.2","pocket":"security"}],"xenial":[{"name":"xterm","version":"322-1ubuntu1.2","description":"X terminal emulator","is_source":true},{"name":"xterm","version":"322-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xterm","version_link":"https://launchpad.net/ubuntu/+source/xterm/322-1ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-27135"]}]},{"id":"CVE-2020-17525","published":"2021-02-10T12:00:00","updated_at":"2025-08-25T23:22:51.018905+00:00","description":"\nSubversion's mod_authz_svn module will crash if the server is using\nin-repository authz rules with the AuthzSVNReposRelativeAccessFile option\nand a client sends a request for a non-existing repository URL. This can\nlead to disruption for users of the service. This issue was fixed in\nmod_dav_svn+mod_authz_svn servers 1.14.1 and mod_dav_svn+mod_authz_svn\nservers 1.10.7","ubuntu_description":"\nThomas Åkesson discovered that Subversion incorrectly handled certain\ninputs. An attacker could possibly use this issue to cause a denial of\nservice.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-5322-1","https://ubuntu.com/security/notices/USN-5445-1","https://www.cve.org/CVERecord?id=CVE-2020-17525"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/subversion/+bug/1915698"],"patches":{"subversion":[]},"tags":{"subversion":["universe-binary"]},"packages":[{"name":"subversion","source":"https://ubuntu.com/security/cve?package=subversion","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=subversion","debian":"https://tracker.debian.org/pkg/subversion","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.14.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.9.7-4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.14.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.7, 1.14.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.9.3-2ubuntu1.3+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.13.0-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.14.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5322-1","USN-5445-1"],"notices":[{"id":"USN-5322-1","title":"Subversion vulnerability","summary":"Subversion could be made to crash if it received specially crafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-03-10T20:21:37.710718","description":"Thomas Akesson discovered that Subversion incorrectly handled certain inputs.\nAn attacker could possibly use this issue to cause a denial of service.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"subversion","version":"1.9.3-2ubuntu1.3+esm1","description":"Advanced version control system","is_source":true},{"name":"libsvn-dev","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"ruby-svn","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"subversion-tools","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-svn","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-svn","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"python-subversion","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libsvn-java","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"subversion","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libsvn-doc","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libsvn1","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libsvn-perl","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"},{"name":"libsvn-ruby1.8","version":"1.9.3-2ubuntu1.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-17525"]},{"id":"USN-5445-1","title":"Subversion vulnerabilities","summary":"Several security issues were fixed in subversion.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-05-26T04:46:55.902489","description":"Ace Olszowka discovered that Subversion incorrectly handled certain\nsvnserve requests. A remote attacker could possibly use this issue to cause\nsvnserver to crash, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2018-11782)\n\nTomas Bortoli discovered that Subversion incorrectly handled certain\nsvnserve requests. A remote attacker could possibly use this issue to cause\nsvnserver to crash, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2019-0203)\n\nThomas Åkesson discovered that Subversion incorrectly handled certain\ninputs. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2020-17525)\n","is_hidden":false,"release_packages":{"focal":[{"name":"subversion","version":"1.13.0-3ubuntu0.2","description":"Advanced version control system","is_source":true},{"name":"libsvn-dev","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"ruby-svn","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"subversion-tools","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"libapache2-mod-svn","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"python-subversion","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"libsvn1","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"subversion","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"libsvn-doc","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"libsvn-java","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"},{"name":"libsvn-perl","version":"1.13.0-3ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.13.0-3ubuntu0.2","pocket":"security"}],"bionic":[{"name":"subversion","version":"1.9.7-4ubuntu1.1","description":"Advanced version control system","is_source":true},{"name":"libsvn-dev","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"ruby-svn","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"subversion-tools","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"libapache2-mod-svn","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"python-subversion","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"libsvn1","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"subversion","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"libsvn-doc","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"libsvn-java","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"},{"name":"libsvn-perl","version":"1.9.7-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/subversion","version_link":"https://launchpad.net/ubuntu/+source/subversion/1.9.7-4ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-17525","CVE-2019-0203","CVE-2018-11782"]}]},{"id":"CVE-2020-36244","published":"2021-02-10T07:15:00","updated_at":"2025-08-26T12:25:41.717789+00:00","description":"\nThe daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a\nheap-based buffer overflow that could allow an attacker to remotely execute\narbitrary code on the DLT-Daemon (versions prior to 2.18.6).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/GENIVI/dlt-daemon/issues/265","https://github.com/GENIVI/dlt-daemon/pull/269","https://github.com/GENIVI/dlt-daemon/commit/af734fe097ed379b0aa5fcf551886b1ce5098052 (v2.18.6)","https://github.com/GENIVI/dlt-daemon/compare/v2.18.5...v2.18.6","https://www.cve.org/CVERecord?id=CVE-2020-36244"],"bugs":[""],"patches":{"dlt-daemon":[]},"tags":{},"packages":[{"name":"dlt-daemon","source":"https://ubuntu.com/security/cve?package=dlt-daemon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dlt-daemon","debian":"https://tracker.debian.org/pkg/dlt-daemon","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-24031","published":"2021-02-10T00:00:00","updated_at":"2025-08-18T17:15:15.587049+00:00","description":"\nIn the Zstandard command-line utility prior to v1.4.1, output files were\ncreated with default permissions. Correct file permissions (matching the\ninput) would only be set at completion time. Output files could therefore\nbe readable or writable to unintended parties.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4760-1","https://ubuntu.com/security/notices/USN-5720-1","https://www.cve.org/CVERecord?id=CVE-2021-24031"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=981404","https://github.com/facebook/zstd/issues/1630"],"patches":{"libzstd":["upstream: https://github.com/facebook/zstd/pull/1644/commits/3968160a916a759c3d3418da533e1b4f8b795343","upstream: https://github.com/facebook/zstd/pull/1644/commits/af80f6dfacafcc2c916ecd57731107221e1f9986"]},"tags":{},"packages":[{"name":"libzstd","source":"https://ubuntu.com/security/cve?package=libzstd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libzstd","debian":"https://tracker.debian.org/pkg/libzstd","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.1+dfsg-1~ubuntu0.16.04.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"bionic","status":"released","description":"1.3.3+dfsg-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.4+dfsg-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.4.5+dfsg-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.4.8+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4760-1","USN-5720-1"],"notices":[{"id":"USN-4760-1","title":"libzstd vulnerabilities","summary":"libzstd could be made to expose sensitive information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-08T18:21:54.225596","description":"It was discovered that libzstd incorrectly handled file permissions. A\nlocal attacker could possibly use this issue to access certain files,\ncontrary to expectations.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libzstd","version":"1.3.3+dfsg-2ubuntu1.2","description":"fast lossless compression algorithm","is_source":true},{"name":"libzstd-dev","version":"1.3.3+dfsg-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2","pocket":"security"},{"name":"libzstd1","version":"1.3.3+dfsg-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2","pocket":"security"},{"name":"libzstd1-dev","version":"1.3.3+dfsg-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2","pocket":"security"},{"name":"libzstd1-udeb","version":"1.3.3+dfsg-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2","pocket":"security"},{"name":"zstd","version":"1.3.3+dfsg-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2","pocket":"security"}],"focal":[{"name":"libzstd","version":"1.4.4+dfsg-3ubuntu0.1","description":"fast lossless compression algorithm","is_source":true},{"name":"libzstd-dev","version":"1.4.4+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.4+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libzstd1","version":"1.4.4+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.4+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libzstd1-udeb","version":"1.4.4+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.4+dfsg-3ubuntu0.1","pocket":"security"},{"name":"zstd","version":"1.4.4+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.4+dfsg-3ubuntu0.1","pocket":"security"}],"groovy":[{"name":"libzstd","version":"1.4.5+dfsg-4ubuntu0.1","description":"fast lossless compression algorithm","is_source":true},{"name":"libzstd-dev","version":"1.4.5+dfsg-4ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.5+dfsg-4ubuntu0.1","pocket":"security"},{"name":"libzstd1","version":"1.4.5+dfsg-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.5+dfsg-4ubuntu0.1","pocket":"security"},{"name":"libzstd1-udeb","version":"1.4.5+dfsg-4ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.5+dfsg-4ubuntu0.1","pocket":"security"},{"name":"zstd","version":"1.4.5+dfsg-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":"https://launchpad.net/ubuntu/+source/libzstd/1.4.5+dfsg-4ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-24031","CVE-2021-24032"]},{"id":"USN-5720-1","title":"Zstandard vulnerabilities","summary":"Zstandard could be made to expose sensitive information\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-11-09T12:00:15.467034","description":"It was discovered that Zstandard was not properly managing file\npermissions when generating output files. A local attacker could\npossibly use this issue to cause a race condition and gain\nunauthorized access to sensitive data.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libzstd","version":"1.3.1+dfsg-1~ubuntu0.16.04.1+esm3","description":"fast lossless compression algorithm","is_source":true},{"name":"zstd","version":"1.3.1+dfsg-1~ubuntu0.16.04.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":null,"pocket":"esm-infra"},{"name":"libzstd1-dev","version":"1.3.1+dfsg-1~ubuntu0.16.04.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":null,"pocket":"esm-infra"},{"name":"libzstd1","version":"1.3.1+dfsg-1~ubuntu0.16.04.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libzstd","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2021-24031","CVE-2021-24032"]}]},{"id":"CVE-2021-0326","published":"2021-02-10T00:00:00","updated_at":"2025-08-25T23:30:10.459636+00:00","description":"\nIn p2p_copy_client_info of p2p.c, there is a possible out of bounds write\ndue to a missing bounds check. This could lead to remote code execution if\nthe target device is performing a Wi-Fi Direct search, with no additional\nexecution privileges needed. User interaction is not needed for\nexploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1\nAndroid-9Android ID: A-172937525","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2021/02/03/4","https://w1.fi/security/2020-2/wpa_supplicant-p2p-group-info-processing-vulnerability.txt","https://w1.fi/security/2020-2/0001-P2P-Fix-copying-of-secondary-device-types-for-P2P-gr.patch","https://w1.fi/cgit/hostap/commit/?id=947272febe24a8f0ea828b5b2f35f13c3821901e","https://ubuntu.com/security/notices/USN-4734-1","https://ubuntu.com/security/notices/USN-4734-2","https://www.cve.org/CVERecord?id=CVE-2021-0326"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=981971"],"patches":{"wpa":["upstream: https://w1.fi/cgit/hostap/commit/?id=947272febe24a8f0ea828b5b2f35f13c3821901e"]},"tags":{},"packages":[{"name":"wpa","source":"https://ubuntu.com/security/cve?package=wpa","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpa","debian":"https://tracker.debian.org/pkg/wpa","statuses":[{"release_codename":"bionic","status":"released","description":"2:2.6-15ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2:2.9-1ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"2:2.9-1ubuntu8.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.1-0ubuntu1.7+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"2:2.9.0-17","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4-0ubuntu6.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-4734-1","USN-4734-2"],"notices":[{"id":"USN-4734-1","title":"wpa_supplicant and hostapd vulnerabilities","summary":"Several security issues were fixed in wpa_supplicant and hostapd.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2021-02-11T22:22:17.120682","description":"It was discovered that wpa_supplicant did not properly handle P2P\n(Wi-Fi Direct) group information in some situations, leading to a\nheap overflow. A physically proximate attacker could use this to cause a\ndenial of service or possibly execute arbitrary code. (CVE-2021-0326)\n\nIt was discovered that hostapd did not properly handle UPnP subscribe\nmessages in some circumstances. An attacker could use this to cause a\ndenial of service. (CVE-2020-12695)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"wpa","version":"2:2.6-15ubuntu2.7","description":"client support for WPA and WPA2","is_source":true},{"name":"hostapd","version":"2:2.6-15ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.6-15ubuntu2.7","pocket":"security"},{"name":"wpagui","version":"2:2.6-15ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.6-15ubuntu2.7","pocket":"security"},{"name":"wpasupplicant","version":"2:2.6-15ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.6-15ubuntu2.7","pocket":"security"},{"name":"wpasupplicant-udeb","version":"2:2.6-15ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.6-15ubuntu2.7","pocket":"security"}],"focal":[{"name":"wpa","version":"2:2.9-1ubuntu4.2","description":"client support for WPA and WPA2","is_source":true},{"name":"hostapd","version":"2:2.9-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu4.2","pocket":"security"},{"name":"wpagui","version":"2:2.9-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu4.2","pocket":"security"},{"name":"wpasupplicant","version":"2:2.9-1ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu4.2","pocket":"security"},{"name":"wpasupplicant-udeb","version":"2:2.9-1ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu4.2","pocket":"security"}],"groovy":[{"name":"wpa","version":"2:2.9-1ubuntu8.1","description":"client support for WPA and WPA2","is_source":true},{"name":"hostapd","version":"2:2.9-1ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu8.1","pocket":"security"},{"name":"wpagui","version":"2:2.9-1ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu8.1","pocket":"security"},{"name":"wpasupplicant","version":"2:2.9-1ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu8.1","pocket":"security"},{"name":"wpasupplicant-udeb","version":"2:2.9-1ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu8.1","pocket":"security"}],"xenial":[{"name":"wpa","version":"2.4-0ubuntu6.7","description":"client support for WPA and WPA2","is_source":true},{"name":"hostapd","version":"1:2.4-0ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.4-0ubuntu6.7","pocket":"security"},{"name":"wpagui","version":"2.4-0ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.4-0ubuntu6.7","pocket":"security"},{"name":"wpasupplicant","version":"2.4-0ubuntu6.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.4-0ubuntu6.7","pocket":"security"},{"name":"wpasupplicant-udeb","version":"2.4-0ubuntu6.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.4-0ubuntu6.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-0326","CVE-2020-12695"]},{"id":"USN-4734-2","title":"wpa_supplicant and hostapd vulnerabilities","summary":"Several security issues were fixed in wpa_supplicant and hostapd.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2021-02-16T21:33:59.019967","description":"USN-4734-1 fixed several vulnerabilities in wpa_supplicant. This\nupdate provides the corresponding update for Ubuntu 14.04 ESM.\n\nIt was discovered that wpa_supplicant did not properly handle P2P\n(Wi-Fi Direct) group information in some situations, leading to a\nheap overflow. A physically proximate attacker could use this to cause a\ndenial of service or possibly execute arbitrary code. (CVE-2021-0326)\n\nIt was discovered that hostapd did not properly handle UPnP subscribe\nmessages in some circumstances. An attacker could use this to cause a\ndenial of service. (CVE-2020-12695)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"wpa","version":"2.1-0ubuntu1.7+esm3","description":"client support for WPA and WPA2","is_source":true},{"name":"hostapd","version":"1:2.1-0ubuntu1.7+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.7+esm3"},{"name":"wpagui","version":"2.1-0ubuntu1.7+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.7+esm3"},{"name":"wpasupplicant-udeb","version":"2.1-0ubuntu1.7+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.7+esm3"},{"name":"wpasupplicant","version":"2.1-0ubuntu1.7+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wpa","version_link":"https://launchpad.net/ubuntu/+source/wpa/2.1-0ubuntu1.7+esm3"}]},"type":"USN","cves_ids":["CVE-2021-0326","CVE-2020-12695"]}]},{"id":"CVE-2020-35498","published":"2021-02-10T00:00:00","updated_at":"2025-08-25T23:26:03.282263+00:00","description":"\nA vulnerability was found in openvswitch. A limitation in the\nimplementation of userspace packet parsing can allow a malicious user to\nsend a specially crafted packet causing the resulting megaflow in the\nkernel to be too wide, potentially causing a denial of service. The highest\nthreat from this vulnerability is to system availability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4729-1","https://www.cve.org/CVERecord?id=CVE-2020-35498"],"bugs":[""],"patches":{"openvswitch":[]},"tags":{},"packages":[{"name":"openvswitch","source":"https://ubuntu.com/security/cve?package=openvswitch","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openvswitch","debian":"https://tracker.debian.org/pkg/openvswitch","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.5.9-0ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.9.8-0ubuntu0.18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.13.1-0ubuntu0.20.04.4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"2.13.1-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4729-1"],"notices":[{"id":"USN-4729-1","title":"Open vSwitch vulnerability","summary":"Open vSwitch could be made to crash or perform unexpectedly if it received\nspecially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-02-10T15:21:32.487646","description":"Joakim Hindersson discovered that Open vSwitch incorrectly parsed certain\nnetwork packets. A remote attacker could use this issue to cause a denial\nof service, or possibly alter packet classification.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openvswitch","version":"2.9.8-0ubuntu0.18.04.2","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-doc","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-pki","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-switch","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-test","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"openvswitch-vtep","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"ovn-central","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"ovn-common","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"ovn-controller-vtep","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"ovn-docker","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"ovn-host","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"python-openvswitch","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"},{"name":"python3-openvswitch","version":"2.9.8-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.8-0ubuntu0.18.04.2","pocket":"security"}],"focal":[{"name":"openvswitch","version":"2.13.1-0ubuntu0.20.04.4","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-doc","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-pki","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-source","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-switch","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-test","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"openvswitch-vtep","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"},{"name":"python3-openvswitch","version":"2.13.1-0ubuntu0.20.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu0.20.04.4","pocket":"security"}],"groovy":[{"name":"openvswitch","version":"2.13.1-0ubuntu1.3","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-doc","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-pki","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-source","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-switch","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-test","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"openvswitch-vtep","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"},{"name":"python3-openvswitch","version":"2.13.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.13.1-0ubuntu1.3","pocket":"security"}],"xenial":[{"name":"openvswitch","version":"2.5.9-0ubuntu0.16.04.3","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-ipsec","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-pki","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-switch","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-test","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"openvswitch-vtep","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"ovn-central","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"ovn-common","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"ovn-docker","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"ovn-host","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"},{"name":"python-openvswitch","version":"2.5.9-0ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.9-0ubuntu0.16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-35498"]}]},{"id":"CVE-2020-27352","published":"2021-02-10T00:00:00","updated_at":"2025-08-25T23:24:59.075230+00:00","description":"\nWhen generating the systemd service units for the docker snap (and other\nsimilar snaps), snapd does not specify Delegate=yes - as a result systemd\nwill move processes from the containers created and managed by these snaps\ninto the cgroup of the main daemon within the snap itself when reloading\nsystem units. This may grant additional privileges to a container within\nthe snap that were not originally intended.","ubuntu_description":"\nGilad Reti and Nimrod Stoler discovered that snapd did not correctly\nspecify cgroup delegation when generating systemd service units for\nvarious container management snaps. This could allow a local attacker to\nescalate privileges via access to arbitrary devices of the container host\nfrom within a compromised or malicious container.","notes":[],"codename":null,"priority":"high","cvss3":9.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.3,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4728-1","https://www.cve.org/CVERecord?id=CVE-2020-27352"],"bugs":["https://bugs.launchpad.net/snapd/+bug/1910456"],"patches":{"snapd":[]},"tags":{},"packages":[{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"bionic","status":"released","description":"2.48.3+18.04","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.48.3+20.04","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"2.48.3+20.10","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.48.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-4728-1"],"notices":[{"id":"USN-4728-1","title":"snapd vulnerability","summary":"An intended access restriction in snapd could be bypassed by container\nmanagement snaps.\n","instructions":"In general, a standard system update will make all the necessary changes.\nOn Ubuntu, snapd will automatically refresh itself to snapd 2.48.3 which is\nunaffected. Affected container management snaps will also automatically\nrefresh which will restart containers and resolve this vulnerability.\n","references":[],"published":"2021-02-10T01:14:00.342130","description":"Gilad Reti and Nimrod Stoler discovered that snapd did not correctly specify cgroup\ndelegation when generating systemd service units for various container\nmanagement snaps. This could allow a local attacker to escalate privileges\nvia access to arbitrary devices of the container host from within a\ncompromised or malicious container.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"snapd","version":"2.48.3+18.04","description":"Daemon and tooling that enable snap packages","is_source":true},{"name":"golang-github-snapcore-snapd-dev","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"golang-github-ubuntu-core-snappy-dev","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"snap-confine","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"snapd","version":"2.48.3+18.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"snapd-xdg-open","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"ubuntu-core-launcher","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"ubuntu-core-snapd-units","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"ubuntu-snappy","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"},{"name":"ubuntu-snappy-cli","version":"2.48.3+18.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+18.04","pocket":"security"}],"focal":[{"name":"snapd","version":"2.48.3+20.04","description":"Daemon and tooling that enable snap packages","is_source":true},{"name":"golang-github-snapcore-snapd-dev","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"golang-github-ubuntu-core-snappy-dev","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"snap-confine","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"snapd","version":"2.48.3+20.04","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"snapd-xdg-open","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"ubuntu-core-launcher","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"ubuntu-core-snapd-units","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"ubuntu-snappy","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"},{"name":"ubuntu-snappy-cli","version":"2.48.3+20.04","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.04","pocket":"security"}],"groovy":[{"name":"snapd","version":"2.48.3+20.10","description":"Daemon and tooling that enable snap packages","is_source":true},{"name":"golang-github-snapcore-snapd-dev","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"golang-github-ubuntu-core-snappy-dev","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"snap-confine","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"snapd","version":"2.48.3+20.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"snapd-xdg-open","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"ubuntu-core-launcher","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"ubuntu-core-snapd-units","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"ubuntu-snappy","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"},{"name":"ubuntu-snappy-cli","version":"2.48.3+20.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3+20.10","pocket":"security"}],"xenial":[{"name":"snapd","version":"2.48.3","description":"Daemon and tooling that enable snap packages","is_source":true},{"name":"golang-github-snapcore-snapd-dev","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"golang-github-ubuntu-core-snappy-dev","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"snap-confine","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"snapd","version":"2.48.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"snapd-xdg-open","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"ubuntu-core-launcher","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"ubuntu-core-snapd-units","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"ubuntu-snappy","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"},{"name":"ubuntu-snappy-cli","version":"2.48.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/snapd","version_link":"https://launchpad.net/ubuntu/+source/snapd/2.48.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-27352"]}]}],"offset":43380,"limit":20,"total_results":79316}