{"cves":[{"id":"CVE-2019-6477","published":"2019-11-20T00:00:00","updated_at":"2025-08-25T23:14:00.061801+00:00","description":"\nWith pipelining enabled each incoming query on a TCP connection requires a\nsimilar resource allocation to a query received via UDP or via TCP without\npipelining enabled. A client using a TCP-pipelined connection to a server\ncould consume more resources than the server has been provisioned to\nhandle. When a TCP connection with a large number of pipelined queries is\nclosed, the load on the server releasing these multiple resources can cause\nit to become unresponsive, even for queries that can be answered\nauthoritatively or from cache. (This is most likely to be perceived as an\nintermittent server problem).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in https://github.com/isc-projects/bind9/commit/761d135ed686601f36fe3d0d4aaa6bf41287bb0f"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://kb.isc.org/docs/cve-2019-6477","https://ubuntu.com/security/notices/USN-4197-1","https://www.cve.org/CVERecord?id=CVE-2019-6477"],"bugs":[""],"patches":{"bind9":[]},"tags":{},"packages":[{"name":"bind9","source":"https://ubuntu.com/security/cve?package=bind9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bind9","debian":"https://tracker.debian.org/pkg/bind9","statuses":[{"release_codename":"bionic","status":"released","description":"1:9.11.3+dfsg-1ubuntu1.11","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1:9.11.5.P1+dfsg-1ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4197-1"],"notices":[{"id":"USN-4197-1","title":"Bind vulnerability","summary":"Bind could be made to consume resources if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-11-21T12:15:37.287655","description":"It was discovered that Bind incorrectly handled certain TCP-pipelined\nqueries. A remote attacker could possibly use this issue to cause Bind to\nconsume resources, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"bind9","version":"1:9.11.3+dfsg-1ubuntu1.11","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"bind9-doc","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"bind9-host","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"bind9utils","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"dnsutils","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libbind-dev","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libbind-export-dev","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libbind9-160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libdns-export1100","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libdns-export1100-udeb","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libdns1100","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libirs-export160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libirs-export160-udeb","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libirs160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisc-export169","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisc-export169-udeb","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisc169","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisccc-export160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisccc-export160-udeb","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisccc160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisccfg-export160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisccfg-export160-udeb","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"libisccfg160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"},{"name":"liblwres160","version":"1:9.11.3+dfsg-1ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.11","pocket":"security"}],"disco":[{"name":"bind9","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"bind9-doc","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"bind9-host","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"bind9utils","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"dnsutils","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libbind-dev","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libbind-export-dev","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libbind9-161","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libdns-export1104","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libdns-export1104-udeb","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libdns1104","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libirs-export161","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libirs-export161-udeb","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libirs161","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisc-export1100","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisc-export1100-udeb","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisc1100","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisccc-export161","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisccc-export161-udeb","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisccc161","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisccfg-export163","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisccfg-export163-udeb","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"libisccfg163","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"},{"name":"liblwres161","version":"1:9.11.5.P1+dfsg-1ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P1+dfsg-1ubuntu2.6"}],"eoan":[{"name":"bind9","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","description":"Internet Domain Name Server","is_source":true},{"name":"bind9","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"bind9-doc","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"bind9-host","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"bind9utils","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"dnsutils","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libbind-dev","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libbind-export-dev","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libbind9-161","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libdns-export1104","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libdns-export1104-udeb","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libdns1104","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libirs-export161","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libirs-export161-udeb","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libirs161","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisc-export1100","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisc-export1100-udeb","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisc1100","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisccc-export161","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisccc-export161-udeb","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisccc161","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisccfg-export163","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisccfg-export163-udeb","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"libisccfg163","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"},{"name":"liblwres161","version":"1:9.11.5.P4+dfsg-5.1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bind9","version_link":"https://launchpad.net/ubuntu/+source/bind9/1:9.11.5.P4+dfsg-5.1ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2019-6477"]}]},{"id":"CVE-2019-16255","published":"2019-11-20T00:00:00","updated_at":"2025-07-11T07:42:12.603765+00:00","description":"\nRuby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows\ncode injection if the first argument (aka the \"command\" argument) to\nShell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can\nexploit this to call an arbitrary Ruby method.","ubuntu_description":"\nIt was discovered that JRuby did not properly sanitize input to Shell#[] and\nits alias Shell#test. An attacker could use this vulnerability to execute\narbitrary commands.","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.ruby-lang.org/en/news/2019/10/01/code-injection-shell-test-cve-2019-16255/","https://ubuntu.com/security/notices/USN-4201-1","https://www.cve.org/CVERecord?id=CVE-2019-16255"],"bugs":[""],"patches":{"ruby2.5":["upstream: https://github.com/ruby/ruby/commit/3af01ae1101e0b8815ae5a106be64b0e82a58640"],"ruby2.3":[],"jruby":[]},"tags":{},"packages":[{"name":"jruby","source":"https://ubuntu.com/security/cve?package=jruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jruby","debian":"https://tracker.debian.org/pkg/jruby","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.6-9+deb8u2build0.14.04.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.1-2~ubuntu16.04.14","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby2.5","source":"https://ubuntu.com/security/cve?package=ruby2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.5","debian":"https://tracker.debian.org/pkg/ruby2.5","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.5.1-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.5.5-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.5.5-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4201-1"],"notices":[{"id":"USN-4201-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-11-26T14:48:39.667359","description":"It was discovered that Ruby incorrectly handled certain files.\nAn attacker could possibly use this issue to pass path matching\nwhat can lead to an unauthorized access. (CVE-2019-15845)\n\nIt was discovered that Ruby incorrectly handled certain regular expressions.\nAn attacker could use this issue to cause a denial of service.\n(CVE-2019-16201)\n\nIt was discovered that Ruby incorrectly handled certain HTTP headers.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16254)\n\nIt was discovered that Ruby incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16255)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-dev","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-doc","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"}],"disco":[{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-dev","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-doc","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"}],"eoan":[{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-dev","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-doc","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"}],"xenial":[{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-dev","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-doc","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-tcltk","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-15845","CVE-2019-16201","CVE-2019-16254","CVE-2019-16255"]}]},{"id":"CVE-2019-16254","published":"2019-11-20T00:00:00","updated_at":"2025-08-25T23:07:31.384797+00:00","description":"\nRuby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows\nHTTP Response Splitting. If a program using WEBrick inserts untrusted input\ninto the response header, an attacker can exploit it to insert a newline\ncharacter to split a header, and inject malicious content to deceive\nclients. NOTE: this issue exists because of an incomplete fix for\nCVE-2017-17742, which addressed the CRLF vector, but did not address an\nisolated CR or an isolated LF.","ubuntu_description":"\nIt was discovered that JRuby mishandled newline characters in HTTP response\nheaders. A remote attacker could use this vulnerability to display malicious\ncontent to HTTP clients.","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.ruby-lang.org/en/news/2019/10/01/http-response-splitting-in-webrick-cve-2019-16254/","https://ubuntu.com/security/notices/USN-4201-1","https://www.cve.org/CVERecord?id=CVE-2019-16254"],"bugs":[""],"patches":{"ruby2.5":["upstream: https://github.com/ruby/ruby/commit/3ce238b5f9795581eb84114dcfbdf4aa086bfecc","upstream: https://github.com/ruby/ruby/commit/f98b3023bd786b4e7dfdb94b573a5f5d3d37d145"],"ruby2.3":[],"jruby":[]},"tags":{},"packages":[{"name":"jruby","source":"https://ubuntu.com/security/cve?package=jruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jruby","debian":"https://tracker.debian.org/pkg/jruby","statuses":[{"release_codename":"trusty","status":"released","description":"1.5.6-9+deb8u2build0.14.04.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.1-2~ubuntu16.04.14","component":null,"pocket":"security"}]},{"name":"ruby2.5","source":"https://ubuntu.com/security/cve?package=ruby2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.5","debian":"https://tracker.debian.org/pkg/ruby2.5","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.5.1-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.5.5-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.5.5-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4201-1"],"notices":[{"id":"USN-4201-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-11-26T14:48:39.667359","description":"It was discovered that Ruby incorrectly handled certain files.\nAn attacker could possibly use this issue to pass path matching\nwhat can lead to an unauthorized access. (CVE-2019-15845)\n\nIt was discovered that Ruby incorrectly handled certain regular expressions.\nAn attacker could use this issue to cause a denial of service.\n(CVE-2019-16201)\n\nIt was discovered that Ruby incorrectly handled certain HTTP headers.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16254)\n\nIt was discovered that Ruby incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16255)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-dev","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-doc","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"}],"disco":[{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-dev","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-doc","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"}],"eoan":[{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-dev","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-doc","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"}],"xenial":[{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-dev","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-doc","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-tcltk","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-15845","CVE-2019-16201","CVE-2019-16254","CVE-2019-16255"]}]},{"id":"CVE-2019-16201","published":"2019-11-20T00:00:00","updated_at":"2025-07-11T07:42:09.129196+00:00","description":"\nWEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6,\nand 2.6.x through 2.6.4 has a regular expression Denial of Service cause by\nlooping/backtracking. A victim must expose a WEBrick server that uses\nDigestAuth to the Internet or a untrusted network.","ubuntu_description":"\nIt was discovered that WEBrick as provided by JRuby was vulnerable to a denial\nof service attack due to catastrophic backtracking in certain regular\nexpressions. An attacker could use this vulnerability to cause JRuby to\nconsume system resources.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.ruby-lang.org/en/news/2019/10/01/webrick-regexp-digestauth-dos-cve-2019-16201/","https://ubuntu.com/security/notices/USN-4201-1","https://www.cve.org/CVERecord?id=CVE-2019-16201"],"bugs":[""],"patches":{"ruby2.5":["upstream: https://github.com/ruby/ruby/commit/36e057e26ef2104bc2349799d6c52d22bb1c7d03","upstream: https://github.com/ruby/ruby/commit/05cdcdc6ec7f0777ba56100308e54e97e277293f"],"ruby2.3":[],"jruby":[]},"tags":{},"packages":[{"name":"jruby","source":"https://ubuntu.com/security/cve?package=jruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jruby","debian":"https://tracker.debian.org/pkg/jruby","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.6-9+deb8u2build0.14.04.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.1-2~ubuntu16.04.14","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby2.5","source":"https://ubuntu.com/security/cve?package=ruby2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.5","debian":"https://tracker.debian.org/pkg/ruby2.5","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.5.1-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.5.5-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.5.5-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4201-1"],"notices":[{"id":"USN-4201-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-11-26T14:48:39.667359","description":"It was discovered that Ruby incorrectly handled certain files.\nAn attacker could possibly use this issue to pass path matching\nwhat can lead to an unauthorized access. (CVE-2019-15845)\n\nIt was discovered that Ruby incorrectly handled certain regular expressions.\nAn attacker could use this issue to cause a denial of service.\n(CVE-2019-16201)\n\nIt was discovered that Ruby incorrectly handled certain HTTP headers.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16254)\n\nIt was discovered that Ruby incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16255)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-dev","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-doc","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"}],"disco":[{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-dev","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-doc","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"}],"eoan":[{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-dev","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-doc","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"}],"xenial":[{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-dev","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-doc","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-tcltk","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-15845","CVE-2019-16201","CVE-2019-16254","CVE-2019-16255"]}]},{"id":"CVE-2019-15845","published":"2019-11-20T00:00:00","updated_at":"2025-08-25T23:07:15.974144+00:00","description":"\nRuby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles\npath checking within File.fnmatch functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.ruby-lang.org/en/news/2019/10/01/nul-injection-file-fnmatch-cve-2019-15845/","https://hackerone.com/reports/449617","https://ubuntu.com/security/notices/USN-4201-1","https://www.cve.org/CVERecord?id=CVE-2019-15845"],"bugs":[""],"patches":{"ruby2.5":["upstream: https://github.com/ruby/ruby/commit/a0a2640b398cffd351f87d3f6243103add66575b","upstream: https://github.com/ruby/ruby/commit/02ea1fdfc70b01189574a4a640eec3c9c81d2417"],"ruby2.3":[],"jruby":[]},"tags":{},"packages":[{"name":"jruby","source":"https://ubuntu.com/security/cve?package=jruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jruby","debian":"https://tracker.debian.org/pkg/jruby","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.1-2~ubuntu16.04.14","component":null,"pocket":"security"}]},{"name":"ruby2.5","source":"https://ubuntu.com/security/cve?package=ruby2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.5","debian":"https://tracker.debian.org/pkg/ruby2.5","statuses":[{"release_codename":"bionic","status":"released","description":"2.5.1-1ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.5.5-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.5.5-4ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4201-1"],"notices":[{"id":"USN-4201-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-11-26T14:48:39.667359","description":"It was discovered that Ruby incorrectly handled certain files.\nAn attacker could possibly use this issue to pass path matching\nwhat can lead to an unauthorized access. (CVE-2019-15845)\n\nIt was discovered that Ruby incorrectly handled certain regular expressions.\nAn attacker could use this issue to cause a denial of service.\n(CVE-2019-16201)\n\nIt was discovered that Ruby incorrectly handled certain HTTP headers.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16254)\n\nIt was discovered that Ruby incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\n(CVE-2019-16255)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-dev","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"},{"name":"ruby2.5-doc","version":"2.5.1-1ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6","pocket":"security"}],"disco":[{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-dev","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"},{"name":"ruby2.5-doc","version":"2.5.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1"}],"eoan":[{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","description":"Interpreter of object-oriented scripting language Ruby","is_source":true},{"name":"libruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-dev","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"},{"name":"ruby2.5-doc","version":"2.5.5-4ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":"https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1"}],"xenial":[{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-dev","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-doc","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"},{"name":"ruby2.3-tcltk","version":"2.3.1-2~ubuntu16.04.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-15845","CVE-2019-16201","CVE-2019-16254","CVE-2019-16255"]}]},{"id":"CVE-2011-3350","published":"2019-11-19T23:15:00","updated_at":"2025-08-25T20:16:41.121439+00:00","description":"\nmasqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and\nsrc/masqmail.c that results in improper privilege dropping.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3350"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=638002","http://article.gmane.org/gmane.mail.masqmail/303"],"patches":{"masqmail":[]},"tags":{},"packages":[{"name":"masqmail","source":"https://ubuntu.com/security/cve?package=masqmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=masqmail","debian":"https://tracker.debian.org/pkg/masqmail","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"0.2.30-1","component":null,"pocket":"security"},{"release_codename":"quantal","status":"released","description":"0.2.30-1","component":null,"pocket":"security"},{"release_codename":"raring","status":"released","description":"0.2.30-1","component":null,"pocket":"security"},{"release_codename":"saucy","status":"released","description":"0.2.30-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.30-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-19126","published":"2019-11-19T22:15:00","updated_at":"2025-08-25T23:09:05.778165+00:00","description":"\nOn the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails\nto ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program\nexecution after a security transition, allowing local attackers to restrict\nthe possible mapping addresses for loaded libraries and thus bypass ASLR\nfor a setuid program.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"introduced in b9eb92ab05204df772eb4929eccd018637c9f3e9,\nso glibc 2.23"}],"codename":null,"priority":"low","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://sourceware.org/ml/libc-alpha/2019-11/msg00649.html","https://ubuntu.com/security/notices/USN-4416-1","https://www.cve.org/CVERecord?id=CVE-2019-19126"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=25204"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=d5dfad4326fc683c813df1e37bbf5cf920591c8e"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"bionic","status":"released","description":"2.27-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.30-0ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.31-0ubuntu7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.31","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.23-0ubuntu11.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4416-1"],"notices":[{"id":"USN-4416-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2020-07-06T18:10:11.630219","description":"Florian Weimer discovered that the GNU C Library incorrectly handled\ncertain memory operations. A remote attacker could use this issue to cause\nthe GNU C Library to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2017-12133)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nSSE2-optimized memmove operations. A remote attacker could use this issue\nto cause the GNU C Library to crash, resulting in a denial of service, or\npossibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2017-18269)\n\nIt was discovered that the GNU C Library incorrectly handled certain\npathname operations. A remote attacker could use this issue to cause the\nGNU C Library to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2018-11236)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nAVX-512-optimized mempcpy operations. A remote attacker could use this\nissue to cause the GNU C Library to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. This issue only affected\nUbuntu 18.04 LTS. (CVE-2018-11237)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nhostname loookups. A remote attacker could use this issue to cause the GNU\nC Library to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19591)\n\nJakub Wilk discovered that the GNU C Library incorrectly handled certain\nmemalign functions. A remote attacker could use this issue to cause the GNU\nC Library to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-6485)\n\nIt was discovered that the GNU C Library incorrectly ignored the\nLD_PREFER_MAP_32BIT_EXEC environment variable after security transitions. A\nlocal attacker could use this issue to bypass ASLR restrictions.\n(CVE-2019-19126)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nregular expressions. A remote attacker could possibly use this issue to\ncause the GNU C Library to crash, resulting in a denial of service. This\nissue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-9169)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nbit patterns. A remote attacker could use this issue to cause the GNU C\nLibrary to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04\nLTS. (CVE-2020-10029)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nsignal trampolines on PowerPC. A remote attacker could use this issue to\ncause the GNU C Library to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2020-1751)\n\nIt was discovered that the GNU C Library incorrectly handled tilde\nexpansion. A remote attacker could use this issue to cause the GNU C\nLibrary to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2020-1752)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"glibc","version":"2.27-3ubuntu1.2","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"glibc-source","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc-bin","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc-dev-bin","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-amd64","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-armel","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-armel","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-i386","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-s390","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-x32","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-i386","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-pic","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-s390","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-udeb","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-x32","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"locales","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"locales-all","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"multiarch-support","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"nscd","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"}],"eoan":[{"name":"glibc","version":"2.30-0ubuntu2.2","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"glibc-source","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc-bin","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc-dev-bin","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-amd64","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-armel","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-amd64","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-armel","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-i386","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-s390","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-x32","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-i386","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-pic","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-s390","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-udeb","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-x32","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"locales","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"locales-all","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"nscd","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"}],"xenial":[{"name":"glibc","version":"2.23-0ubuntu11.2","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-i386","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12133","CVE-2017-18269","CVE-2018-11236","CVE-2018-11237","CVE-2018-19591","CVE-2018-6485","CVE-2019-19126","CVE-2019-9169","CVE-2020-10029","CVE-2020-1751","CVE-2020-1752"]}]},{"id":"CVE-2011-3349","published":"2019-11-19T22:15:00","updated_at":"2025-08-25T20:16:41.121439+00:00","description":"\nlightdm before 0.9.6 writes in .dmrc and Xauthority files using root\npermissions while the files are in user controlled folders. A local user\ncan overwrite root-owned files via a symlink, which can allow possible\nprivilege escalation.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"The code is quite different, but it looks like the version in\nnatty is affected"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-3349"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=639151"],"patches":{"lightdm":[]},"tags":{},"packages":[{"name":"lightdm","source":"https://ubuntu.com/security/cve?package=lightdm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lightdm","debian":"https://tracker.debian.org/pkg/lightdm","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"released","description":"0.9.5-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.1.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"1.1.1-0ubuntu4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2924","published":"2019-11-19T22:15:00","updated_at":"2025-08-25T20:15:05.006130+00:00","description":"\nfoomatic-rip filter v4.0.12 and prior used insecurely creates temporary\nfiles for storage of PostScript data by rendering the data when the debug\nmode was enabled. This flaw may be exploited by a local attacker to conduct\nsymlink attacks by overwriting arbitrary files accessible with the\nprivileges of the user running the foomatic-rip universal print filter.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"C variant"},{"author":"jdstrand","note":"requires debug mode"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/07/28/9","https://www.cve.org/CVERecord?id=CVE-2011-2924"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=726426"],"patches":{"foomatic-filters":[]},"tags":{"maverick":["symlink-restriction"],"natty":["symlink-restriction"],"oneiric":["symlink-restriction"],"devel":["symlink-restriction"]},"packages":[{"name":"foomatic-filters","source":"https://ubuntu.com/security/cve?package=foomatic-filters","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=foomatic-filters","debian":"https://tracker.debian.org/pkg/foomatic-filters","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-10768","published":"2019-11-19T21:15:00","updated_at":"2025-08-26T12:11:08.131176+00:00","description":"\nIn AngularJS before 1.7.9 the function `merge()` could be tricked into\nadding or modifying properties of `Object.prototype` using a `__proto__`\npayload.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://snyk.io/vuln/SNYK-JS-ANGULAR-534884","https://www.cve.org/CVERecord?id=CVE-2019-10768"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=945249"],"patches":{"angular.js":["upstream: https://github.com/angular/angular.js/commit/add78e62004e80bb1e16ab2dfe224afa8e513bc3"]},"tags":{},"packages":[{"name":"angular.js","source":"https://ubuntu.com/security/cve?package=angular.js","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=angular.js","debian":"https://tracker.debian.org/pkg/angular.js","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.7.9-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2923","published":"2019-11-19T21:15:00","updated_at":"2025-08-25T20:15:05.006130+00:00","description":"\nfoomatic-rip filter, all versions, used insecurely creates temporary files\nfor storage of PostScript data by rendering the data when the debug mode\nwas enabled. This flaw may be exploited by a local attacker to conduct\nsymlink attacks by overwriting arbitrary files accessible with the\nprivileges of the user running the foomatic-rip universal print filter.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"perl variant"},{"author":"jdstrand","note":"requires debug mode"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/07/28/9","https://www.cve.org/CVERecord?id=CVE-2011-2923"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=726426"],"patches":{"foomatic-filters":[]},"tags":{"maverick":["symlink-restriction"],"natty":["symlink-restriction"],"oneiric":["symlink-restriction"],"devel":["symlink-restriction"]},"packages":[{"name":"foomatic-filters","source":"https://ubuntu.com/security/cve?package=foomatic-filters","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=foomatic-filters","debian":"https://tracker.debian.org/pkg/foomatic-filters","statuses":[{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was ignored]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2922","published":"2019-11-19T19:15:00","updated_at":"2025-08-25T20:15:05.006130+00:00","description":"\nktsuss versions 1.4 and prior spawns the GTK interface to run as root. This\ncan allow a local attacker to escalate privileges to root and use the\n\"GTK_MODULES\" environment variable to possibly execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/08/16/2","https://www.cve.org/CVERecord?id=CVE-2011-2922"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626178"],"patches":{"ktsuss":[]},"tags":{},"packages":[{"name":"ktsuss","source":"https://ubuntu.com/security/cve?package=ktsuss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ktsuss","debian":"https://tracker.debian.org/pkg/ktsuss","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-18934","published":"2019-11-19T18:15:00","updated_at":"2025-08-25T23:08:54.868619+00:00","description":"\nUnbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module\nthat can cause shell code execution after receiving a specially crafted\nanswer. This issue can only be triggered if unbound was compiled with\n`--enable-ipsecmod` support, and ipsecmod is enabled and used in the\nconfiguration.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only vulnerable if compiled with --enable-ipsecmod, which is\nnot the case on Ubuntu"}],"codename":null,"priority":"high","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://nlnetlabs.nl/downloads/unbound/CVE-2019-18934.txt","https://www.cve.org/CVERecord?id=CVE-2019-18934"],"bugs":[""],"patches":{"unbound":[]},"tags":{"unbound":["universe-binary"]},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-1000236","published":"2019-11-19T17:15:00","updated_at":"2025-08-26T11:53:34.843055+00:00","description":"\nNode-cookie-signature before 1.0.6 is affected by a timing attack due to\nthe type of comparison used.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://nodesecurity.io/advisories/134","https://www.cve.org/CVERecord?id=CVE-2016-1000236"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=838618"],"patches":{"node-cookie-signature":["upstream: https://github.com/tj/node-cookie-signature/commit/39791081692e9e14aa62855369e1c7f80fbfd50e"]},"tags":{},"packages":[{"name":"node-cookie-signature","source":"https://ubuntu.com/security/cve?package=node-cookie-signature","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-cookie-signature","debian":"https://tracker.debian.org/pkg/node-cookie-signature","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.1.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.1.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6135","published":"2019-11-19T17:15:00","updated_at":"2025-08-25T20:41:07.944136+00:00","description":"\nRubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete\narbitrary files during the startup process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2013/03/02/1","https://bugzilla.novell.com/show_bug.cgi?id=804722","http://blog.phusion.nl/2013/03/05/phusion-passenger-4-0-beta-1-and-2-arbitrary-file-deletion-vulnerability/","https://www.cve.org/CVERecord?id=CVE-2012-6135"],"bugs":[""],"patches":{"ruby-passenger":["upstream: https://github.com/FooBarWidget/passenger/commit/8c6693e0818772c345c979840d28312c2edd4ba4#commitcomment-2643541"]},"tags":{},"packages":[{"name":"ruby-passenger","source":"https://ubuntu.com/security/cve?package=ruby-passenger","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-passenger","debian":"https://tracker.debian.org/pkg/ruby-passenger","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.0 rc4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6071","published":"2019-11-19T17:15:00","updated_at":"2025-08-25T20:40:43.828479+00:00","description":"\nnuSOAP before 0.7.3-5 does not properly check the hostname of a cert.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2012-6071"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696707"],"patches":{"nusoap":["vendor: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696707"]},"tags":{},"packages":[{"name":"nusoap","source":"https://ubuntu.com/security/cve?package=nusoap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nusoap","debian":"https://tracker.debian.org/pkg/nusoap","statuses":[{"release_codename":"vivid","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.7.3-5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.7.3-5]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-6070","published":"2019-11-19T17:15:00","updated_at":"2025-08-25T20:40:38.686000+00:00","description":"\nFalconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow\nremote attackers to interfere with security checks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2012-6070"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=696681"],"patches":{"falconpl":["upstream: http://git.falconpl.org/cgit.cgi/falcon/commit/?id=93d94a88a8bb073e609327ceca704b313e1309ff"]},"tags":{},"packages":[{"name":"falconpl","source":"https://ubuntu.com/security/cve?package=falconpl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=falconpl","debian":"https://tracker.debian.org/pkg/falconpl","statuses":[{"release_codename":"vivid","status":"not-affected","description":"0.9.6.9-git20120606-2","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.9.6.9-git20120606-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.6.9-git20120606-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"not-affected","description":"0.9.6.9-git20120606-2","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [0.9.6.9-git20120606-2]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-2921","published":"2019-11-19T17:15:00","updated_at":"2025-08-25T20:15:00.667564+00:00","description":"\nktsuss versions 1.4 and prior has the uid set to root and does not drop\nprivileges prior to executing user specified commands, which can result in\ncommand execution with root privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"high","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2011/08/16/2","https://www.cve.org/CVERecord?id=CVE-2011-2921"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626178"],"patches":{"ktsuss":[]},"tags":{},"packages":[{"name":"ktsuss","source":"https://ubuntu.com/security/cve?package=ktsuss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ktsuss","debian":"https://tracker.debian.org/pkg/ktsuss","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-5439","published":"2019-11-19T16:15:00","updated_at":"2025-08-25T21:22:26.131472+00:00","description":"\nMultiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit\nprior to 0.3.7 via a crafted configuration file that will bypass\nNon-eXecutable bit NX, stack smashing protector SSP, and address space\nlayout randomization ASLR protection mechanisms, which could let a\nmalicious user execute arbitrary code.","ubuntu_description":"\nIt was discovered that SniffIt incorrectly handled certain configuration\nfiles. An attacker could possibly use this issue to execute arbitrary\ncode.","notes":[{"author":"sbeattie","note":"sniffit is not setuid, so this issue only affects\nconfigurations where a user is only permitted to run a subset of\nadministrative (e.g. using a sudo configuration that only allows a\nuser to run sniffit)."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://hmarco.org/bugs/CVE-2014-5439-sniffit_0.3.7-stack-buffer-overflow.html","https://ubuntu.com/security/notices/USN-4652-1","https://www.cve.org/CVERecord?id=CVE-2014-5439"],"bugs":[""],"patches":{"sniffit":[]},"tags":{},"packages":[{"name":"sniffit","source":"https://ubuntu.com/security/cve?package=sniffit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sniffit","debian":"https://tracker.debian.org/pkg/sniffit","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.3.7.beta-17+deb8u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.3.7.beta-20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.3.7.beta-19ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4652-1"],"notices":[{"id":"USN-4652-1","title":"SniffIt vulnerability","summary":"SniffIt could be made to crash or run programs as root if it\nopened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-11-30T16:24:06.285893","description":"It was discovered that SniffIt incorrectly handled certain configuration\nfiles. An attacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"sniffit","version":"0.3.7.beta-19ubuntu0.1","description":"packet sniffer and monitoring tool","is_source":true},{"name":"sniffit","version":"0.3.7.beta-19ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sniffit","version_link":"https://launchpad.net/ubuntu/+source/sniffit/0.3.7.beta-19ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-5439"]}]},{"id":"CVE-2012-0843","published":"2019-11-19T16:15:00","updated_at":"2025-08-25T20:26:03.903798+00:00","description":"\nuzbl: Information disclosure via world-readable cookies storage file","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2012-0843"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=659379"],"patches":{"uzbl":[]},"tags":{},"packages":[{"name":"uzbl","source":"https://ubuntu.com/security/cve?package=uzbl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=uzbl","debian":"https://tracker.debian.org/pkg/uzbl","statuses":[{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"0.0.0~git.20111128-2","component":null,"pocket":"security"},{"release_codename":"quantal","status":"not-affected","description":"0.0.0~git.20111128-2","component":null,"pocket":"security"},{"release_codename":"raring","status":"not-affected","description":"0.0.0~git.20111128-2","component":null,"pocket":"security"},{"release_codename":"saucy","status":"not-affected","description":"0.0.0~git.20111128-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.0.0~git.20111128-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":47580,"limit":20,"total_results":79316}