{"cves":[{"id":"CVE-2020-14147","published":"2020-06-15T18:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nAn integer overflow in the getnum function in lua_struct.c in Redis before\n6.0.3 allows context-dependent attackers with permission to run Lua code in\na Redis session to cause a denial of service (memory corruption and\napplication crash) or possibly bypass intended sandbox restrictions via a\nlarge number, which triggers a stack-based buffer overflow. NOTE: this\nissue exists because of a CVE-2015-8080 regression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/antirez/redis/pull/6875","https://github.com/antirez/redis/commit/ef764dde1cca2f25d00686673d1bc89448819571","https://www.cve.org/CVERecord?id=CVE-2020-14147"],"bugs":[""],"patches":{"redis":[]},"tags":{},"packages":[{"name":"redis","source":"https://ubuntu.com/security/cve?package=redis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=redis","debian":"https://tracker.debian.org/pkg/redis","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"5:6.0.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14155","published":"2020-06-15T17:15:00","updated_at":"2025-08-25T23:20:25.447625+00:00","description":"\nlibpcre in PCRE before 8.44 allows an integer overflow via a large number\nafter a (?C substring.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.pcre.org/original/changelog.txt","https://ubuntu.com/security/notices/USN-5425-1","https://www.cve.org/CVERecord?id=CVE-2020-14155"],"bugs":["https://bugs.gentoo.org/717920"],"patches":{"pcre3":["upstream: https://vcs.pcre.org/pcre?view=revision&revision=1761"]},"tags":{},"packages":[{"name":"pcre3","source":"https://ubuntu.com/security/cve?package=pcre3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre3","debian":"https://tracker.debian.org/pkg/pcre3","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:8.31-2ubuntu2.3+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"8.44,2:8.39-13","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:8.39-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2:8.39-12ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2:8.39-13","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:8.38-3.1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"groovy","status":"not-affected","description":"2:8.39-13","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2:8.39-13","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2:8.39-13","component":null,"pocket":"security"}]}],"notices_ids":["USN-5425-1"],"notices":[{"id":"USN-5425-1","title":"PCRE vulnerabilities","summary":"Several security issues were fixed in PCRE.\n","instructions":"After a standard system update you need to restart applications using PCRE,\nsuch as the Apache HTTP server and Nginx, to make all the necessary\nchanges.\n","references":[],"published":"2022-05-17T15:31:52.642391","description":"Yunho Kim discovered that PCRE incorrectly handled memory when \nhandling certain regular expressions. An attacker could possibly use\nthis issue to cause applications using PCRE to expose sensitive\ninformation. This issue only affects Ubuntu 18.04 LTS, \nUbuntu 20.04 LTS, Ubuntu 21.10 and Ubuntu 22.04 LTS. (CVE-2019-20838)\n\nIt was discovered that PCRE incorrectly handled memory when \nhandling certain regular expressions. An attacker could possibly use\nthis issue to cause applications using PCRE to have unexpected \nbehavior. This issue only affects Ubuntu 14.04 ESM, Ubuntu 16.04 ESM,\nUbuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14155)\n","is_hidden":false,"release_packages":{"impish":[{"name":"pcre3","version":"2:8.39-13ubuntu0.21.10.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"}],"trusty":[{"name":"pcre3","version":"1:8.31-2ubuntu2.3+esm1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"libpcre3","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre3-dev","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"pcregrep","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcrecpp0","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"pcre3","version":"2:8.39-13ubuntu0.22.04.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"}],"xenial":[{"name":"pcre3","version":"2:8.38-3.1ubuntu0.1~esm1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre3-dev","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre3","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcrecpp0v5","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre16-3","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre32-3","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"}],"bionic":[{"name":"pcre3","version":"2:8.39-9ubuntu0.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"}],"focal":[{"name":"pcre3","version":"2:8.39-12ubuntu0.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14155","CVE-2019-20838"]}]},{"id":"CVE-2020-14154","published":"2020-06-15T17:15:00","updated_at":"2025-08-25T23:20:25.447625+00:00","description":"\nMutt before 1.14.3 proceeds with a connection even if, in response to a\nGnuTLS certificate prompt, the user rejects an expired intermediate\ncertificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://lists.mutt.org/pipermail/mutt-announce/Week-of-Mon-20200608/000022.html","http://www.mutt.org","https://ubuntu.com/security/notices/USN-4401-1","https://www.cve.org/CVERecord?id=CVE-2020-14154"],"bugs":[""],"patches":{"mutt":["upstream: https://github.com/muttmua/mutt/commit/bb0e6277a45a5d4c3a30d3b968eeb31d78124e95","upstream: https://github.com/muttmua/mutt/commit/5fccf603ebcf352ba783136d6b2d2600d811fb3b","upstream: https://github.com/muttmua/mutt/commit/f64ec1deefb67d471a642004e102cd1c501a1db3"]},"tags":{},"packages":[{"name":"mutt","source":"https://ubuntu.com/security/cve?package=mutt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mutt","debian":"https://tracker.debian.org/pkg/mutt","statuses":[{"release_codename":"bionic","status":"released","description":"1.9.4-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1.10.1-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.13.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.5.24-1ubuntu0.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-4401-1"],"notices":[{"id":"USN-4401-1","title":"Mutt vulnerabilities","summary":"Several security issues were fixed in Mutt.\n","instructions":"After a standard system update you need to restart mutt to make all the necessary changes.\n","references":[],"published":"2020-06-22T14:20:02.247988","description":"It was discovered that Mutt incorrectly handled certain requests.\nAn attacker could possibly use this issue to enable MITM attacks.\n(CVE-2020-14093)\n\nIt was discovered that Mutt incorrectly handled certain requests.\nAn attacker could possibly use this issue to proceeds with a connection\neven if the user rejects an expired intermediate certificate.\n(CVE-2020-14154)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"mutt","version":"1.9.4-3ubuntu0.2","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.9.4-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.9.4-3ubuntu0.2","pocket":"security"}],"eoan":[{"name":"mutt","version":"1.10.1-2.1ubuntu0.1","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.10.1-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.10.1-2.1ubuntu0.1"}],"focal":[{"name":"mutt","version":"1.13.2-1ubuntu0.1","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.13.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.13.2-1ubuntu0.1","pocket":"security"}],"precise":[{"name":"mutt","version":"1.5.21-5ubuntu2.4","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.5.21-5ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.21-5ubuntu2.4"},{"name":"mutt-patched","version":"1.5.21-5ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.21-5ubuntu2.4"}],"xenial":[{"name":"mutt","version":"1.5.24-1ubuntu0.3","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.5.24-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.24-1ubuntu0.3","pocket":"security"},{"name":"mutt-patched","version":"1.5.24-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.24-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14093","CVE-2020-14154"]}]},{"id":"CVE-2020-14153","published":"2020-06-15T17:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nIn IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an\nout-of-bounds array read for certain table pointers.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"patch in libjpeg9 9d appears to be:\n- entropy->ac_cur_tbls[blkn] = entropy->ac_derived_tbls[compptr->ac_tbl_no];\n+ entropy->ac_cur_tbls[blkn] =\t/* AC needs no table when not present */\n+\tcinfo->lim_Se ? entropy->ac_derived_tbls[compptr->ac_tbl_no] : NULL;\n\nper upstream libjpeg-turbo bug, libjpeg-turbo is not vulnerable\nto this issue"},{"author":"ccdm94","note":"due to the same reasoning provided by the libjpeg-turbo upstream in issue\nhttps://github.com/libjpeg-turbo/libjpeg-turbo/issues/445, it is safe to\nassume that libjpeg6b is also not vulnerable to this."}],"codename":null,"priority":"low","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.ijg.org/files/jpegsrc.v9d.tar.gz","https://ubuntu.com/security/notices/USN-5336-1","https://www.cve.org/CVERecord?id=CVE-2020-14153"],"bugs":["https://bugs.gentoo.org/727908","https://github.com/libjpeg-turbo/libjpeg-turbo/issues/445"],"patches":{"libjpeg6b":[],"libjpeg-turbo":[],"libjpeg9":[]},"tags":{},"packages":[{"name":"libjpeg6b","source":"https://ubuntu.com/security/cve?package=libjpeg6b","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg6b","debian":"https://tracker.debian.org/pkg/libjpeg6b","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libjpeg-turbo","source":"https://ubuntu.com/security/cve?package=libjpeg-turbo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg-turbo","debian":"https://tracker.debian.org/pkg/libjpeg-turbo","statuses":[{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libjpeg9","source":"https://ubuntu.com/security/cve?package=libjpeg9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg9","debian":"https://tracker.debian.org/pkg/libjpeg9","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:9b-1ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9d","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5336-1"],"notices":[{"id":"USN-5336-1","title":"libjpeg9 vulnerabilities","summary":"Several security issues were fixed in libjpeg9.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-03-23T12:40:00.726468","description":"Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly\nvalidate the input image's size. An attacker could possibly use this issue to\ncause a denial of service or execute arbitrary code. (CVE-2016-3616)\n\nIt was discovered that the cjpeg utility in libjpeg9 incorrectly handled\ncertain input. An attacker could possibly use these issues to cause a denial of\nservice. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)\n\nIt was discovered that the cjpeg utility in libjpeg9 incorrectly handled\nmemory when supplied with certain input. An attacker could possibly use these\nissues to cause a denial of service or execute arbitrary code.\n(CVE-2018-11213, CVE-2018-11214)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libjpeg9","version":"1:9b-1ubuntu1+esm1","description":"Independent JPEG Group's JPEG runtime library","is_source":true},{"name":"libjpeg-progs","version":"1:9b-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg9","version_link":null,"pocket":"esm-apps"},{"name":"libjpeg9","version":"1:9b-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg9","version_link":null,"pocket":"esm-apps"},{"name":"libjpeg9-dev","version":"1:9b-1ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg9","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-14153","CVE-2018-11212","CVE-2020-14152","CVE-2018-11813","CVE-2016-3616","CVE-2018-11214","CVE-2018-11213"]}]},{"id":"CVE-2020-14152","published":"2020-06-15T17:15:00","updated_at":"2025-07-11T07:43:23.884634+00:00","description":"\nIn IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in\ndjpeg does not honor the max_memory_to_use setting, possibly causing\nexcessive memory consumption.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"looks like this was fixed a long time ago in libjpeg-turbo"}],"codename":null,"priority":"low","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.ijg.org/files/jpegsrc.v9d.tar.gz","https://ubuntu.com/security/notices/USN-5497-1","https://ubuntu.com/security/notices/USN-5553-1","https://ubuntu.com/security/notices/USN-5497-2","https://ubuntu.com/security/notices/USN-5336-1","https://www.cve.org/CVERecord?id=CVE-2020-14152"],"bugs":["https://bugs.gentoo.org/727908"],"patches":{"libjpeg6b":[],"libjpeg-turbo":["upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/da2a27ef056a0179cbd80f9146e58b89403d9933"],"libjpeg9":[]},"tags":{},"packages":[{"name":"libjpeg6b","source":"https://ubuntu.com/security/cve?package=libjpeg6b","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg6b","debian":"https://tracker.debian.org/pkg/libjpeg6b","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6b1-4ubuntu1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:6b2-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"libjpeg-turbo","source":"https://ubuntu.com/security/cve?package=libjpeg-turbo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg-turbo","debian":"https://tracker.debian.org/pkg/libjpeg-turbo","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.0.3-0ubuntu1.20.04.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.5.2-0ubuntu5.18.04.4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.0.3-0ubuntu1.19.10.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.0-0ubuntu2.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1:1.5.1-2+deb9u1, 1:1.5.2-2+den10u1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.4.2-0ubuntu3.4+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"mantic","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.0.3-0ubuntu2","component":null,"pocket":"security"}]},{"name":"libjpeg9","source":"https://ubuntu.com/security/cve?package=libjpeg9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg9","debian":"https://tracker.debian.org/pkg/libjpeg9","statuses":[{"release_codename":"impish","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:9b-1ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9d","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5336-1","USN-5497-1","USN-5553-1","USN-5497-2"],"notices":[{"id":"USN-5336-1","title":"libjpeg9 vulnerabilities","summary":"Several security issues were fixed in libjpeg9.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-03-23T12:40:00.726468","description":"Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly\nvalidate the input image's size. An attacker could possibly use this issue to\ncause a denial of service or execute arbitrary code. (CVE-2016-3616)\n\nIt was discovered that the cjpeg utility in libjpeg9 incorrectly handled\ncertain input. An attacker could possibly use these issues to cause a denial of\nservice. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)\n\nIt was discovered that the cjpeg utility in libjpeg9 incorrectly handled\nmemory when supplied with certain input. An attacker could possibly use these\nissues to cause a denial of service or execute arbitrary code.\n(CVE-2018-11213, CVE-2018-11214)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libjpeg9","version":"1:9b-1ubuntu1+esm1","description":"Independent JPEG Group's JPEG runtime library","is_source":true},{"name":"libjpeg-progs","version":"1:9b-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg9","version_link":null,"pocket":"esm-apps"},{"name":"libjpeg9","version":"1:9b-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg9","version_link":null,"pocket":"esm-apps"},{"name":"libjpeg9-dev","version":"1:9b-1ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg9","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-14153","CVE-2018-11212","CVE-2020-14152","CVE-2018-11813","CVE-2016-3616","CVE-2018-11214","CVE-2018-11213"]},{"id":"USN-5497-1","title":"Libjpeg6b vulnerabilities","summary":"Several security issues were fixed in Libjpeg6b.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-06-30T12:54:31.249903","description":"It was discovered that Libjpeg6b was not properly performing bounds\nchecks when compressing PPM and Targa image files. An attacker could\npossibly use this issue to cause a denial of service.\n(CVE-2018-11212)\n\nChijin Zhou discovered that Libjpeg6b was incorrectly handling the\nEOF character in input data when generating JPEG files. An attacker\ncould possibly use this issue to force the execution of a large loop,\nforce excessive memory consumption, and cause a denial of service.\n(CVE-2018-11813)\n\nSheng Shu and Dongdong She discovered that Libjpeg6b was not properly\nlimiting the amount of memory being used when it was performing\ndecompression or multi-pass compression operations. An attacker could\npossibly use this issue to force excessive memory consumption and\ncause a denial of service. (CVE-2020-14152)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libjpeg6b","version":"6b1-4ubuntu1+esm1","description":"library for handling JPEG files","is_source":true},{"name":"libjpeg62","version":"6b1-4ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg6b","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg62-dev","version":"6b1-4ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg6b","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-11212","CVE-2020-14152","CVE-2018-11813","CVE-2018-11213","CVE-2018-11214"]},{"id":"USN-5553-1","title":"libjpeg-turbo vulnerabilities","summary":"Several security issues were fixed in libjpeg-turbo.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-08-08T12:06:20.547943","description":"It was discovered that libjpeg-turbo was not properly handling EOF characters,\nwhich could lead to excessive memory consumption through the execution of a\nlarge loop. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2018-11813)\n\nIt was discovered that libjpeg-turbo was not properly performing bounds\ncheck operations, which could lead to a heap-based buffer overread. If a user\nor automated system were tricked into opening a specially crafted file, an\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 14.04 ESM. (CVE-2018-14498)\n\nIt was discovered that libjpeg-turbo was not properly limiting the amount of\nmain memory being consumed by the system during decompression or multi-pass\ncompression operations, which could lead to excessive memory consumption. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2020-14152)\n\nIt was discovered that libjpeg-turbo was not properly setting variable sizes\nwhen performing certain kinds of encoding operations, which could lead to a\nstack-based buffer overflow. If a user or automated system were tricked into\nopening a specially crafted file, an attacker could possibly use this issue to\ncause a denial of service. (CVE-2020-17541)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libjpeg-turbo","version":"1.3.0-0ubuntu2.1+esm2","description":"library for handling JPEG files","is_source":true},{"name":"libjpeg-turbo8","version":"1.3.0-0ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg-turbo-progs","version":"1.3.0-0ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg-turbo8-dev","version":"1.3.0-0ubuntu2.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libturbojpeg","version":"1.3.0-0ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg-turbo-test","version":"1.3.0-0ubuntu2.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libjpeg-turbo","version":"1.4.2-0ubuntu3.4+esm1","description":"library for handling JPEG files","is_source":true},{"name":"libjpeg-turbo8","version":"1.4.2-0ubuntu3.4+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg-turbo-progs","version":"1.4.2-0ubuntu3.4+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg-turbo8-dev","version":"1.4.2-0ubuntu3.4+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libturbojpeg","version":"1.4.2-0ubuntu3.4+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"},{"name":"libjpeg-turbo-test","version":"1.4.2-0ubuntu3.4+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg-turbo","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-17541","CVE-2020-14152","CVE-2018-14498","CVE-2018-11813"]},{"id":"USN-5497-2","title":"Libjpeg6b vulnerabilities","summary":"Several security issues were fixed in Libjpeg6b.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-06-30T14:35:28.146557","description":"USN-5497-1 fixed vulnerabilities in Libjpeg6b. This update provides\nthe corresponding updates for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Libjpeg6b was not properly performing bounds\n checks when compressing PPM and Targa image files. An attacker could\n possibly use this issue to cause a denial of service.\n (CVE-2018-11212)\n\n Chijin Zhou discovered that Libjpeg6b was incorrectly handling the\n EOF character in input data when generating JPEG files. An attacker\n could possibly use this issue to force the execution of a large loop,\n force excessive memory consumption, and cause a denial of service.\n (CVE-2018-11813)\n\n Sheng Shu and Dongdong She discovered that Libjpeg6b was not properly\n limiting the amount of memory being used when it was performing\n decompression or multi-pass compression operations. An attacker could\n possibly use this issue to force excessive memory consumption and\n cause a denial of service. (CVE-2020-14152)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libjpeg6b","version":"1:6b2-2ubuntu0.1~esm1","description":"library for handling JPEG files","is_source":true},{"name":"libjpeg62","version":"1:6b2-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg6b","version_link":null,"pocket":"esm-apps"},{"name":"libjpeg62-dev","version":"1:6b2-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libjpeg6b","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-11813","CVE-2018-11213","CVE-2018-11214","CVE-2018-11212","CVE-2020-14152"]}]},{"id":"CVE-2020-14151","published":"2020-06-15T17:15:00","updated_at":"2025-08-04T19:35:03.540442+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2018-11813. Reason: This candidate is a duplicate of CVE-2018-11813.\nNotes: All CVE users should reference [ID] instead of this candidate. All\nreferences and descriptions in this candidate have been removed to prevent\naccidental usage","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"appears to be a duplicate of CVE-2018-11813"}],"codename":null,"priority":"low","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.ijg.org/files/jpegsrc.v9d.tar.gz","https://www.cve.org/CVERecord?id=CVE-2020-14151"],"bugs":["https://bugs.gentoo.org/727908"],"patches":{"libjpeg6b":[],"libjpeg-turbo":["upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/909a8cfc7bca9b2e6707425bdb74da997e8fa499"],"libjpeg9":[]},"tags":{},"packages":[{"name":"libjpeg-turbo","source":"https://ubuntu.com/security/cve?package=libjpeg-turbo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg-turbo","debian":"https://tracker.debian.org/pkg/libjpeg-turbo","statuses":[{"release_codename":"eoan","status":"not-affected","description":"2.0.3-0ubuntu1.19.10.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.0.3-0ubuntu1.20.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libjpeg6b","source":"https://ubuntu.com/security/cve?package=libjpeg6b","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg6b","debian":"https://tracker.debian.org/pkg/libjpeg6b","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"libjpeg9","source":"https://ubuntu.com/security/cve?package=libjpeg9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libjpeg9","debian":"https://tracker.debian.org/pkg/libjpeg9","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:9d-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9d","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14150","published":"2020-06-15T17:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nGNU Bison before 3.5.4 allows attackers to cause a denial of service\n(application crash). NOTE: there is a risk only if Bison is used with\nuntrusted input, and an observed bug happens to cause unsafe behavior with\na specific compiler/architecture. The bug reports were intended to show\nthat a crash may occur in Bison itself, not that a crash may occur in code\nthat is generated by Bison.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/info-gnu/2020-04/msg00000.html","https://www.cve.org/CVERecord?id=CVE-2020-14150"],"bugs":["https://bugs.gentoo.org/717936"],"patches":{"bison":[]},"tags":{},"packages":[{"name":"bison","source":"https://ubuntu.com/security/cve?package=bison","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bison","debian":"https://tracker.debian.org/pkg/bison","statuses":[{"release_codename":"impish","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:3.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2:3.6.1+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14034","published":"2020-06-15T17:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nAn issue was discovered in janus-gateway (aka Janus WebRTC Server) through\n0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long\nvalue in an SDP Offer packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/meetecho/janus-gateway/pull/2229","https://github.com/meetecho/janus-gateway/commit/dacb4edfad8e77f73b64d8c175cca0a7796ebf80","https://github.com/meetecho/janus-gateway/blob/v0.10.0/utils.c#L381","https://github.com/meetecho/janus-gateway/blob/v0.10.0/utils.c#L401","https://www.cve.org/CVERecord?id=CVE-2020-14034"],"bugs":[""],"patches":{"janus":[]},"tags":{},"packages":[{"name":"janus","source":"https://ubuntu.com/security/cve?package=janus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=janus","debian":"https://tracker.debian.org/pkg/janus","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14033","published":"2020-06-15T17:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nAn issue was discovered in janus-gateway (aka Janus WebRTC Server) through\n0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a\nBuffer Overflow via a crafted RTSP server.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/meetecho/janus-gateway/pull/2229","https://github.com/meetecho/janus-gateway/commit/dacb4edfad8e77f73b64d8c175cca0a7796ebf80","https://github.com/meetecho/janus-gateway/blob/v0.10.0/plugins/janus_streaming.c#L6117","https://github.com/meetecho/janus-gateway/blob/v0.10.0/plugins/janus_streaming.c#L6166","https://www.cve.org/CVERecord?id=CVE-2020-14033"],"bugs":[""],"patches":{"janus":[]},"tags":{},"packages":[{"name":"janus","source":"https://ubuntu.com/security/cve?package=janus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=janus","debian":"https://tracker.debian.org/pkg/janus","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.10.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-20838","published":"2020-06-15T17:15:00","updated_at":"2025-07-11T07:42:31.688561+00:00","description":"\nlibpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when\nUTF is disabled, and \\X or \\R has more than one fixed quantifier, a related\nissue to CVE-2019-20454.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.pcre.org/original/changelog.txt","https://ubuntu.com/security/notices/USN-5425-1","https://www.cve.org/CVERecord?id=CVE-2019-20838"],"bugs":["https://bugs.gentoo.org/717920"],"patches":{"pcre3":["upstream: https://vcs.pcre.org/pcre?view=revision&revision=1740"]},"tags":{},"packages":[{"name":"pcre3","source":"https://ubuntu.com/security/cve?package=pcre3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre3","debian":"https://tracker.debian.org/pkg/pcre3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:8.39-9ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2:8.39-12ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.43","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2:8.39-13ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2:8.39-13ubuntu0.21.10.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5425-1"],"notices":[{"id":"USN-5425-1","title":"PCRE vulnerabilities","summary":"Several security issues were fixed in PCRE.\n","instructions":"After a standard system update you need to restart applications using PCRE,\nsuch as the Apache HTTP server and Nginx, to make all the necessary\nchanges.\n","references":[],"published":"2022-05-17T15:31:52.642391","description":"Yunho Kim discovered that PCRE incorrectly handled memory when \nhandling certain regular expressions. An attacker could possibly use\nthis issue to cause applications using PCRE to expose sensitive\ninformation. This issue only affects Ubuntu 18.04 LTS, \nUbuntu 20.04 LTS, Ubuntu 21.10 and Ubuntu 22.04 LTS. (CVE-2019-20838)\n\nIt was discovered that PCRE incorrectly handled memory when \nhandling certain regular expressions. An attacker could possibly use\nthis issue to cause applications using PCRE to have unexpected \nbehavior. This issue only affects Ubuntu 14.04 ESM, Ubuntu 16.04 ESM,\nUbuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14155)\n","is_hidden":false,"release_packages":{"impish":[{"name":"pcre3","version":"2:8.39-13ubuntu0.21.10.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-13ubuntu0.21.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.21.10.1","pocket":"security"}],"trusty":[{"name":"pcre3","version":"1:8.31-2ubuntu2.3+esm1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"libpcre3","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre3-dev","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"pcregrep","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcrecpp0","version":"1:8.31-2ubuntu2.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"pcre3","version":"2:8.39-13ubuntu0.22.04.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-13ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-13ubuntu0.22.04.1","pocket":"security"}],"xenial":[{"name":"pcre3","version":"2:8.38-3.1ubuntu0.1~esm1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre3-dev","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre3","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcrecpp0v5","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre16-3","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"},{"name":"libpcre32-3","version":"2:8.38-3.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":null,"pocket":"esm-infra"}],"bionic":[{"name":"pcre3","version":"2:8.39-9ubuntu0.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-9ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-9ubuntu0.1","pocket":"security"}],"focal":[{"name":"pcre3","version":"2:8.39-12ubuntu0.1","description":"Perl 5 Compatible Regular Expression Library","is_source":true},{"name":"pcregrep","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre3-dev","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre3","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcrecpp0v5","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre16-3","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"},{"name":"libpcre32-3","version":"2:8.39-12ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pcre3","version_link":"https://launchpad.net/ubuntu/+source/pcre3/2:8.39-12ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14155","CVE-2019-20838"]}]},{"id":"CVE-2018-21245","published":"2020-06-15T17:15:00","updated_at":"2025-07-11T07:41:00.442867+00:00","description":"\nPound before 2.8 allows HTTP request smuggling, a related issue to\nCVE-2016-10711.","ubuntu_description":"","notes":[{"author":"leosilva","note":"patch is the same as in CVE-2016-10711 in jessie"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://admin.hostpoint.ch/pipermail/pound_apsis.ch/2018-May/000054.html","https://ubuntu.com/security/notices/USN-4702-1","https://www.cve.org/CVERecord?id=CVE-2018-21245"],"bugs":[""],"patches":{"pound":[]},"tags":{},"packages":[{"name":"pound","source":"https://ubuntu.com/security/cve?package=pound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pound","debian":"https://tracker.debian.org/pkg/pound","statuses":[{"release_codename":"xenial","status":"released","description":"2.6-6.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.8-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.8-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.12-7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.12-7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.12-7","component":null,"pocket":"security"}]}],"notices_ids":["USN-4702-1"],"notices":[{"id":"USN-4702-1","title":"Pound vulnerabilities","summary":"Several security issues were fixed in pound.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-01-25T12:37:01.343248","description":"It was discovered that Pound incorrectly handled certain HTTP requests\nA remote attacker could use it to retrieve some sensitive\ninformation. (CVE-2016-10711, CVE-2018-21245)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"pound","version":"2.6-6.1ubuntu0.1","description":"reverse proxy, load balancer and HTTPS front-end for Web servers","is_source":true},{"name":"pound","version":"2.6-6.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pound","version_link":"https://launchpad.net/ubuntu/+source/pound/2.6-6.1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-21245","CVE-2016-10711"]}]},{"id":"CVE-2020-13999","published":"2020-06-15T16:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library)\n1.0.12 allows an integer overflow and denial of service via a crafted EMF\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://libemf.sourceforge.net/index.html","https://sourceforge.net/p/libemf/code/HEAD/tree/","https://sourceforge.net/p/libemf/news/2020/06/release-of-libemf-1013/","https://sourceforge.net/projects/libemf/","https://www.cve.org/CVERecord?id=CVE-2020-13999"],"bugs":[""],"patches":{"libemf":[]},"tags":{},"packages":[{"name":"libemf","source":"https://ubuntu.com/security/cve?package=libemf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libemf","debian":"https://tracker.debian.org/pkg/libemf","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.0.13-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-16848","published":"2020-06-15T15:15:00","updated_at":"2025-08-25T22:49:23.429034+00:00","description":"\nA Denial of Service (DoS) condition is possible in OpenStack Mistral in\nversions up to and including 7.0.3. Submitting a specially crafted workflow\ndefinition YAML file containing nested anchors can lead to resource\nexhaustion culminating in a denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1645332","https://bugs.launchpad.net/mistral/+bug/1785657","https://www.cve.org/CVERecord?id=CVE-2018-16848","https://ubuntu.com/security/notices/USN-7465-1"],"bugs":[""],"patches":{"mistral":[]},"tags":{},"packages":[{"name":"mistral","source":"https://ubuntu.com/security/cve?package=mistral","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mistral","debian":"https://tracker.debian.org/pkg/mistral","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"6.0.0-0ubuntu1.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"10.0.0-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"10.0.0-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"10.0.0-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"10.0.0-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"10.0.0-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-7465-1"],"notices":[{"id":"USN-7465-1","title":"Mistral vulnerabilities","summary":"Several security issues were fixed in Mistral.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2025-04-28T12:07:52.963214","description":"It was discovered that Mistral incorrectly handled nested anchors in YAML\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-16848)\n\nPierre Gaxatte discovered that Mistral incorrectly handled erroneous SSH\nprivate key filename commands. An attacker could possibly use this issue to\nexpose sensitive information. (CVE-2018-16849)\n\nIt was discovered that Mistral incorrectly handled the permissions of\nsensitive log files. An attacker could possibly use this issue to expose\nsensitive information. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2019-3866)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"mistral","version":"6.0.0-0ubuntu1.1+esm1","description":"OpenStack Workflow service - API","is_source":true},{"name":"python-mistral-lib","version":"0.4.0-0ubuntu1+esm1","description":"Mistral shared routines and utilities","is_source":true},{"name":"mistral-api","version":"6.0.0-0ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-common","version":"6.0.0-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-engine","version":"6.0.0-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-event-engine","version":"6.0.0-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-executor","version":"6.0.0-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"python-mistral","version":"6.0.0-0ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"python-mistral-lib","version":"0.4.0-0ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-mistral-lib","version_link":null,"pocket":"esm-apps"},{"name":"python-mistral-lib-doc","version":"0.4.0-0ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-mistral-lib","version_link":null,"pocket":"esm-apps"},{"name":"python3-mistral-lib","version":"0.4.0-0ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-mistral-lib","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"mistral","version":"2.0.0-1ubuntu2+esm1","description":"OpenStack Workflow service - API","is_source":true},{"name":"mistral-api","version":"2.0.0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-common","version":"2.0.0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-engine","version":"2.0.0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"mistral-executor","version":"2.0.0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"},{"name":"python-mistral","version":"2.0.0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mistral","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-3866","CVE-2018-16848","CVE-2018-16849"]}]},{"id":"CVE-2017-18869","published":"2020-06-15T15:15:00","updated_at":"2025-07-11T07:38:59.897184+00:00","description":"\nA TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could\nallow a local attacker to trick it into descending into unintended\ndirectories via symlink attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":2.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863985","https://bugzilla.redhat.com/show_bug.cgi?id=1611614","https://github.com/isaacs/chownr/issues/14","https://snyk.io/vuln/npm:chownr:20180731","https://www.cve.org/CVERecord?id=CVE-2017-18869"],"bugs":[""],"patches":{"node-chownr":[]},"tags":{},"packages":[{"name":"node-chownr","source":"https://ubuntu.com/security/cve?package=node-chownr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-chownr","debian":"https://tracker.debian.org/pkg/node-chownr","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.1.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14093","published":"2020-06-15T05:15:00","updated_at":"2025-08-25T23:20:25.447625+00:00","description":"\nMutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via\na PREAUTH response.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.mutt.org","https://ubuntu.com/security/notices/USN-4401-1","https://www.cve.org/CVERecord?id=CVE-2020-14093"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=962897"],"patches":{"mutt":["upstream: https://github.com/muttmua/mutt/commit/3e88866dc60b5fa6aaba6fd7c1710c12c1c3cd01"]},"tags":{},"packages":[{"name":"mutt","source":"https://ubuntu.com/security/cve?package=mutt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mutt","debian":"https://tracker.debian.org/pkg/mutt","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.9.4-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1.10.1-2.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.13.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.5.24-1ubuntu0.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-4401-1"],"notices":[{"id":"USN-4401-1","title":"Mutt vulnerabilities","summary":"Several security issues were fixed in Mutt.\n","instructions":"After a standard system update you need to restart mutt to make all the necessary changes.\n","references":[],"published":"2020-06-22T14:20:02.247988","description":"It was discovered that Mutt incorrectly handled certain requests.\nAn attacker could possibly use this issue to enable MITM attacks.\n(CVE-2020-14093)\n\nIt was discovered that Mutt incorrectly handled certain requests.\nAn attacker could possibly use this issue to proceeds with a connection\neven if the user rejects an expired intermediate certificate.\n(CVE-2020-14154)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"mutt","version":"1.9.4-3ubuntu0.2","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.9.4-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.9.4-3ubuntu0.2","pocket":"security"}],"eoan":[{"name":"mutt","version":"1.10.1-2.1ubuntu0.1","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.10.1-2.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.10.1-2.1ubuntu0.1"}],"focal":[{"name":"mutt","version":"1.13.2-1ubuntu0.1","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.13.2-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.13.2-1ubuntu0.1","pocket":"security"}],"precise":[{"name":"mutt","version":"1.5.21-5ubuntu2.4","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.5.21-5ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.21-5ubuntu2.4"},{"name":"mutt-patched","version":"1.5.21-5ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.21-5ubuntu2.4"}],"xenial":[{"name":"mutt","version":"1.5.24-1ubuntu0.3","description":"text-based mailreader supporting MIME, GPG, PGP and threading","is_source":true},{"name":"mutt","version":"1.5.24-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.24-1ubuntu0.3","pocket":"security"},{"name":"mutt-patched","version":"1.5.24-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/mutt","version_link":"https://launchpad.net/ubuntu/+source/mutt/1.5.24-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14093","CVE-2020-14154"]}]},{"id":"CVE-2020-14060","published":"2020-06-14T21:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction\nbetween serialization gadgets and typing, related to\noadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/issues/2688","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2020-14060"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"impish","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2020-14062","published":"2020-06-14T20:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction\nbetween serialization gadgets and typing, related to\ncom.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/issues/2704","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2020-14062"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"impish","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2020-14061","published":"2020-06-14T20:15:00","updated_at":"2025-08-26T12:19:31.338224+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction\nbetween serialization gadgets and typing, related to\noracle.jms.AQjmsQueueConnectionFactory,\noracle.jms.AQjmsXATopicConnectionFactory,\noracle.jms.AQjmsTopicConnectionFactory,\noracle.jms.AQjmsXAQueueConnectionFactory, and\noracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/issues/2698","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2020-14061"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"impish","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.11.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2020-16122","published":"2020-06-13T01:14:00","updated_at":"2025-08-25T23:22:18.658833+00:00","description":"\nPackageKit's apt backend mistakenly treated all local debs as trusted. The\napt security model is based on repository trust and not on the contents of\nindividual files. On sites with configured PolicyKit rules this may allow\nusers to install malicious packages.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4538-1","https://www.cve.org/CVERecord?id=CVE-2020-16122"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/packagekit/+bug/1882098"],"patches":{"packagekit":[]},"tags":{},"packages":[{"name":"packagekit","source":"https://ubuntu.com/security/cve?package=packagekit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=packagekit","debian":"https://tracker.debian.org/pkg/packagekit","statuses":[{"release_codename":"bionic","status":"released","description":"1.1.9-1ubuntu2.18.04.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.1.13-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-4538-1"],"notices":[{"id":"USN-4538-1","title":"PackageKit vulnerabilities","summary":"Several security issues were fixed in PackageKit.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2020-09-24T13:03:59.073876","description":"Vaisha Bernard discovered that PackageKit incorrectly handled certain\nmethods. A local attacker could use this issue to learn the MIME type of\nany file on the system. (CVE-2020-16121)\n\nSami Niemimäki discovered that PackageKit incorrectly handled local deb\npackages. A local user could possibly use this issue to install untrusted\npackages, contrary to expectations. (CVE-2020-16122)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"packagekit","version":"1.1.9-1ubuntu2.18.04.6","description":"Provides a package management service","is_source":true},{"name":"gir1.2-packagekitglib-1.0","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"gstreamer1.0-packagekit","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"libpackagekit-glib2-18","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"libpackagekit-glib2-dev","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"packagekit","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"packagekit-command-not-found","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"packagekit-docs","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"packagekit-gtk3-module","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"},{"name":"packagekit-tools","version":"1.1.9-1ubuntu2.18.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.9-1ubuntu2.18.04.6","pocket":"security"}],"focal":[{"name":"packagekit","version":"1.1.13-2ubuntu1.1","description":"Provides a package management service","is_source":true},{"name":"gir1.2-packagekitglib-1.0","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"gstreamer1.0-packagekit","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"libpackagekit-glib2-18","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"libpackagekit-glib2-dev","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"packagekit","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"packagekit-command-not-found","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"packagekit-docs","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"packagekit-gtk3-module","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"},{"name":"packagekit-tools","version":"1.1.13-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/1.1.13-2ubuntu1.1","pocket":"security"}],"xenial":[{"name":"packagekit","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","description":"Provides a package management service","is_source":true},{"name":"gir1.2-packagekitglib-1.0","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"gstreamer1.0-packagekit","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"libpackagekit-glib2-16","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"libpackagekit-glib2-dev","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"packagekit","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"packagekit-backend-aptcc","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"packagekit-backend-smart","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"packagekit-docs","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"packagekit-gtk3-module","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"packagekit-tools","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"},{"name":"python3-packagekit","version":"0.8.17-4ubuntu6~gcc5.4ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/packagekit","version_link":"https://launchpad.net/ubuntu/+source/packagekit/0.8.17-4ubuntu6~gcc5.4ubuntu1.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-16121","CVE-2020-16122"]}]},{"id":"CVE-2020-4050","published":"2020-06-12T16:15:00","updated_at":"2025-08-26T12:26:12.553652+00:00","description":"\nIn affected versions of WordPress, misuse of the `set-screen-option`\nfilter's return value allows arbitrary user meta fields to be saved. It\ndoes require an admin to install a plugin that would misuse the filter.\nOnce installed, it can be leveraged by low privileged users. This has been\npatched in version 5.4.2, along with all the previously affected versions\nvia a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18,\n4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34,\n3.7.34).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":3.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://core.trac.wordpress.org/changeset/47951","https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4vpv-fgg2-gcqc","https://github.com/WordPress/wordpress-develop/commit/b8dea76b495f0072523106c6ec46b9ea0d2a0920","https://wordpress.org/news/2020/06/wordpress-5-4-2-security-and-maintenance-release/","https://www.cve.org/CVERecord?id=CVE-2020-4050"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=962685"],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.4.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.0+dfsg1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":45320,"limit":20,"total_results":79316}