{"cves":[{"id":"CVE-2019-12483","published":"2019-05-30T23:29:00","updated_at":"2025-08-26T12:11:38.939272+00:00","description":"\nAn issue was discovered in GPAC 0.7.1. There is a heap-based buffer\noverflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in\nodf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1249","https://www.cve.org/CVERecord?id=CVE-2019-12483"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-12482","published":"2019-05-30T23:29:00","updated_at":"2025-08-26T12:11:38.939272+00:00","description":"\nAn issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference\nin the function gf_isom_get_original_format_type at isomedia/drm_sample.c\nin libgpac.a, as demonstrated by MP4Box.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1249","https://www.cve.org/CVERecord?id=CVE-2019-12482"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-12481","published":"2019-05-30T23:29:00","updated_at":"2025-08-26T12:11:38.939272+00:00","description":"\nAn issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference\nin the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by\nMP4Box.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gpac/gpac/issues/1249","https://www.cve.org/CVERecord?id=CVE-2019-12481"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.0.1+dfsg1-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-12456","published":"2019-05-30T14:29:00","updated_at":"2026-07-04T07:46:37.379165+00:00","description":"\nAn issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in\ndrivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It\nallows local users to cause a denial of service or possibly have\nunspecified other impact by changing the value of ioc_number between two\nkernel reads of that value, aka a \"double fetch\" vulnerability. NOTE: a\nthird party reports that this is unexploitable because the doubly fetched\nvalue is not used","ubuntu_description":"","notes":[{"author":"tyhicks","note":"There seems to be no security impact as the ioc_number is never used\nafter the \"double fetch\""}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lkml.org/lkml/2019/5/29/1164","https://www.cve.org/CVERecord?id=CVE-2019-12456"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1717182#c3"],"patches":{"linux":["break-fix: f92363d12359498f9a9960511de1a550f0ec41c2 f9e3ebeea4521652318af903cddeaf033527e93e"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-gcp-edge":[],"linux-aws-hwe":[],"linux-oracle":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"double fetched value is not used","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-12455","published":"2019-05-30T04:29:00","updated_at":"2026-07-04T07:46:37.379165+00:00","description":"\nAn issue was discovered in sunxi_divs_clk_setup in\ndrivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. There is\nan unchecked kstrndup of derived_name, which might allow an attacker to\ncause a denial of service (NULL pointer dereference and system crash).\nNOTE: This id is disputed as not being an issue because “The memory\nallocation that was not checked is part of a code that only runs at boot\ntime, before user processes are started. Therefore, there is no possibility\nfor an unprivileged user to control it, and no denial of service.”","ubuntu_description":"","notes":[{"author":"tyhicks","note":"This issue has a questionable security impact. The memory allocation\nis in the module init path and it isn't clear if it is actually vulnerable to\nan attacker.\nThis issue only affects kernels built with CONFIG_CLK_SUNXI_CLOCKS\nenabled. Ubuntu does not enable that config option in any kernels."}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=fcdf445ff42f036d22178b49cf64e92d527c1330","https://www.mail-archive.com/linux-kernel@vger.kernel.org/msg2010240.html","https://www.cve.org/CVERecord?id=CVE-2019-12455"],"bugs":[""],"patches":{"linux":["break-fix: - fcdf445ff42f036d22178b49cf64e92d527c1330"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-gcp-edge":[],"linux-aws-hwe":[],"linux-oracle":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"CONFIG_CLK_SUNXI_CLOCKS is not enabled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-12454","published":"2019-05-30T04:29:00","updated_at":"2026-07-04T07:47:12.674104+00:00","description":"\nAn issue was discovered in wcd9335_codec_enable_dec in\nsound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses\nkstrndup instead of kmemdup_nul, which allows attackers to have an\nunspecified impact via unknown vectors. NOTE: The vendor disputes this\nissues as not being a vulnerability because switching to kmemdup_nul()\nwould only fix a security issue if the source string wasn't NUL-terminated,\nwhich is not the case","ubuntu_description":"","notes":[{"author":"tyhicks","note":"There's no security impact here from what I can tell. I've requested\nthat MITRE reject this CVE."}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://git.kernel.org/pub/scm/linux/kernel/git/broonie/sound.git/commit/?h=for-5.3&id=a54988113985ca22e414e132054f234fc8a92604","https://lkml.org/lkml/2019/5/29/705","https://www.cve.org/CVERecord?id=CVE-2019-12454"],"bugs":[""],"patches":{"linux":["break-fix: - a54988113985ca22e414e132054f234fc8a92604"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-gcp-edge":[],"linux-aws-hwe":[],"linux-oracle":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present, introduced in 5.1-rc1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"no security impact","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9866","published":"2019-05-29T17:29:00","updated_at":"2025-08-25T23:16:47.245792+00:00","description":"\nAn issue was discovered in GitLab Community and Enterprise Edition 11.x\nbefore 11.7.7 and 11.8.x before 11.8.3. It allows Information Disclosure.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"affects 11.4 and later"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/03/20/critical-security-release-gitlab-11-dot-8-dot-3-released/","https://www.cve.org/CVERecord?id=CVE-2019-9866"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=925196"],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.8.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9858","published":"2019-05-29T17:29:00","updated_at":"2025-08-26T12:17:58.854071+00:00","description":"\nRemote code execution was discovered in Horde Groupware Webmail 5.2.22 and\n5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image\nupload in forms. When the Horde_Form_Type_image method onSubmit() is called\non uploads, it invokes the functions getImage() and _getUpload(), which\nuses unsanitized user input as a path to save the image. The unsanitized\nPOST parameter object[photo][img][file] is saved in the $upload[img][file]\nPHP variable, allowing an attacker to manipulate the $tmp_file passed to\nmove_uploaded_file() to save the uploaded file. By setting the parameter to\n(for example) ../usr/share/horde/static/bd.php, one can write a PHP\nbackdoor inside the web root. The static/ destination folder is a good\ncandidate to drop the backdoor because it is always writable in Horde\ninstallations. (The unsanitized POST parameter went probably unnoticed\nbecause it's never submitted by the forms, which default to securely using\na random path.)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ssd-disclosure.com/archives/3814/ssd-advisory-horde-groupware-webmail-authenticated-arbitrary-file-injection-to-rce","https://github.com/horde/Form/commit/c916ba979ad1613d76a9407dd0b67968a9594c0e","http://packetstormsecurity.com/files/152476/Horde-Form-Shell-Upload.html","https://lists.debian.org/debian-lts-announce/2019/06/msg00007.html","https://seclists.org/bugtraq/2019/Jun/31","https://ssd-disclosure.com/?p=3814&preview=true","https://www.debian.org/security/2019/dsa-4468","https://www.cve.org/CVERecord?id=CVE-2019-9858"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=930321"],"patches":{"php-horde-form":[]},"tags":{},"packages":[{"name":"php-horde-form","source":"https://ubuntu.com/security/cve?package=php-horde-form","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-horde-form","debian":"https://tracker.debian.org/pkg/php-horde-form","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.0.18-3.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.18-3.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9732","published":"2019-05-29T17:29:00","updated_at":"2025-08-25T23:16:18.636329+00:00","description":"\nAn issue was discovered in GitLab Community and Enterprise Edition 10.x\n(starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, and\n11.8.x before 11.8.1. It has Incorrect Access Control.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"affects v10.0.3 and later"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/03/14/gitlab-11-8-2-released/","https://about.gitlab.com/blog/categories/releases/","https://www.cve.org/CVERecord?id=CVE-2019-9732"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9485","published":"2019-05-29T17:29:00","updated_at":"2025-08-25T23:16:03.214045+00:00","description":"\nAn issue was discovered in GitLab Community and Enterprise Edition before\n11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Insecure\nPermissions.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"Affects 10.8 and later"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","https://www.cve.org/CVERecord?id=CVE-2019-9485"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9221","published":"2019-05-29T17:29:00","updated_at":"2025-08-25T23:15:57.883256+00:00","description":"\nAn issue was discovered in GitLab Community and Enterprise Edition before\n11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect\nAccess Control (issue 3 of 5).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","https://www.cve.org/CVERecord?id=CVE-2019-9221"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.8.2-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9218","published":"2019-05-29T16:29:00","updated_at":"2025-08-25T23:15:53.270088+00:00","description":"\nAn issue was discovered in GitLab Community and Enterprise Edition before\n11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect\nAccess Control (issue 1 of 5).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","https://about.gitlab.com/blog/categories/releases/","https://www.cve.org/CVERecord?id=CVE-2019-9218"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924447"],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.8.2-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9177","published":"2019-05-29T16:29:00","updated_at":"2025-08-04T19:34:53.243538+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none.\nReason: This candidate was withdrawn by its CNA. Further investigation\nshowed that it was not a security issue. Notes: none","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/","https://about.gitlab.com/blog/categories/releases/","https://www.cve.org/CVERecord?id=CVE-2019-9177"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=924447"],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.8.2-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7549","published":"2019-05-29T16:29:00","updated_at":"2025-08-25T23:14:35.670094+00:00","description":"\nAn issue was discovered in GitLab Community and Enterprise Edition 10.x and\n11.x before 11.5.10, 11.6.x before 11.6.8, and 11.7.x before 11.7.3. It has\nIncorrect Access Control. The GitLab pipelines feature is vulnerable to\nauthorization issues that allow unauthorized users to view job information.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"Affects GitLab 10.1 and later"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/2019/01/31/security-release-gitlab-11-dot-7-dot-3-released/","https://about.gitlab.com/blog/categories/releases/","https://www.cve.org/CVERecord?id=CVE-2019-7549"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921059"],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"11.5.10+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-12439","published":"2019-05-29T15:29:00","updated_at":"2026-09-18T16:19:34.260363+00:00","description":"\nbubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in\n/tmp as a mount point. In some particular configurations (related to\nXDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other\nusers from executing bubblewrap or potentially execute code.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"Possibly mitigated by symlink restrictions"}],"codename":null,"priority":"low","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/projectatomic/bubblewrap/releases/tag/v0.3.3","https://www.cve.org/CVERecord?id=CVE-2019-12439","https://ubuntu.com/security/notices/USN-8779-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923557","https://github.com/projectatomic/bubblewrap/issues/304","https://bugzilla.redhat.com/show_bug.cgi?id=1695963"],"patches":{"bubblewrap":["upstream: https://github.com/projectatomic/bubblewrap/commit/efc89e3b939b4bde42c10f065f6b7b02958ed50e"]},"tags":{},"packages":[{"name":"bubblewrap","source":"https://ubuntu.com/security/cve?package=bubblewrap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bubblewrap","debian":"https://tracker.debian.org/pkg/bubblewrap","statuses":[{"release_codename":"bionic","status":"released","description":"0.2.1-1ubuntu0.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.3.1-4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.1-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8779-1"],"notices":[{"id":"USN-8779-1","title":"Bubblewrap vulnerabilities","summary":"Several security issues were fixed in Bubblewrap.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-17T15:50:32.679141","description":"It was discovered that Bubblewrap incorrectly handled certain temporary\ndirectories. A local attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code. This issue only affected\nUbuntu 18.04 LTS. (CVE-2019-12439)\n\nIt was discovered that Bubblewrap incorrectly handled certain symlinks\nduring sandbox setup. A local attacker could possibly use this issue to\ncreate files outside of the sandbox. (CVE-2026-87766)","is_hidden":false,"release_packages":{"bionic":[{"name":"bubblewrap","version":"0.2.1-1ubuntu0.1+esm2","description":"Low-level unprivileged sandboxing tool used by Flatpak and similar projects","is_source":true},{"name":"bubblewrap","version":"0.2.1-1ubuntu0.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bubblewrap","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"bubblewrap","version":"0.4.0-1ubuntu4.1+esm2","description":"Low-level unprivileged sandboxing tool used by Flatpak and similar projects","is_source":true},{"name":"bubblewrap","version":"0.4.0-1ubuntu4.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bubblewrap","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"bubblewrap","version":"0.6.1-1ubuntu0.2","description":"Low-level unprivileged sandboxing tool used by Flatpak and similar projects","is_source":true},{"name":"bubblewrap","version":"0.6.1-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bubblewrap","version_link":"https://launchpad.net/ubuntu/+source/bubblewrap/0.6.1-1ubuntu0.2","pocket":"security"}],"noble":[{"name":"bubblewrap","version":"0.9.0-1ubuntu0.2","description":"Low-level unprivileged sandboxing tool used by Flatpak and similar projects","is_source":true},{"name":"bubblewrap","version":"0.9.0-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bubblewrap","version_link":"https://launchpad.net/ubuntu/+source/bubblewrap/0.9.0-1ubuntu0.2","pocket":"security"}],"resolute":[{"name":"bubblewrap","version":"0.11.1-1ubuntu0.2","description":"Low-level unprivileged sandboxing tool used by Flatpak and similar projects","is_source":true},{"name":"bubblewrap","version":"0.11.1-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bubblewrap","version_link":"https://launchpad.net/ubuntu/+source/bubblewrap/0.11.1-1ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-12439","CVE-2026-87766"]}]},{"id":"CVE-2019-12450","published":"2019-05-29T00:00:00","updated_at":"2025-08-25T23:03:39.866899+00:00","description":"\nfile_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does\nnot properly restrict file permissions while a copy operation is in\nprogress. Instead, default permissions are used.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4014-1","https://ubuntu.com/security/notices/USN-4014-2","https://www.cve.org/CVERecord?id=CVE-2019-12450"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929753"],"patches":{"glib2.0":["upstream: https://gitlab.gnome.org/GNOME/glib/commit/d8f8f4d637ce43f8699ba94c9b7648beda0ca174"]},"tags":{},"packages":[{"name":"glib2.0","source":"https://ubuntu.com/security/cve?package=glib2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=glib2.0","debian":"https://tracker.debian.org/pkg/glib2.0","statuses":[{"release_codename":"disco","status":"released","description":"2.60.0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.56.4-0ubuntu0.18.04.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.58.1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.40.2-0ubuntu1.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.48.2-0ubuntu4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4014-2","USN-4014-1"],"notices":[{"id":"USN-4014-2","title":"GLib vulnerability","summary":"GLib could be made to expose sensitive information if it\nreceived a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-06-11T11:38:55.614569","description":"USN-4014-1 fixed a vulnerability in GLib. This update provides\nthe corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GLib incorrectly handled certain files.\n An attacker could possibly use this issue to access sensitive information.\n","is_hidden":false,"release_packages":{"precise":[{"name":"glib2.0","version":"2.32.4-0ubuntu1.2","description":"GLib Input, Output and Streaming Library (fam module)","is_source":true},{"name":"libglib2.0-0","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libglib2.0-0-refdbg","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libglib2.0-data","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libglib2.0-udeb","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libgio-fam","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libglib2.0-doc","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libglib2.0-bin","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"},{"name":"libglib2.0-dev","version":"2.32.4-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.32.4-0ubuntu1.2"}],"trusty":[{"name":"glib2.0","version":"2.40.2-0ubuntu1.1+esm1","description":"GLib Input, Output and Streaming Library (fam module)","is_source":true},{"name":"libglib2.0-0","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-0-refdbg","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-data","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-udeb","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-tests","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libgio-fam","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-doc","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-bin","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"},{"name":"libglib2.0-dev","version":"2.40.2-0ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1+esm1"}]},"type":"USN","cves_ids":["CVE-2019-12450"]},{"id":"USN-4014-1","title":"GLib vulnerability","summary":"GLib could be made to expose sensitive information if it\nreceived a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-06-10T18:50:30.783212","description":"It was discovered that GLib incorrectly handled certain files.\nAn attacker could possibly use this issue to access sensitive information.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"glib2.0","version":"2.56.4-0ubuntu0.18.04.3","description":"GLib Input, Output and Streaming Library (fam module)","is_source":true},{"name":"libglib2.0-0","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-bin","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-data","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-dev","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-dev-bin","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-doc","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-tests","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"},{"name":"libglib2.0-udeb","version":"2.56.4-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.56.4-0ubuntu0.18.04.3","pocket":"security"}],"cosmic":[{"name":"glib2.0","version":"2.58.1-2ubuntu0.1","description":"GLib Input, Output and Streaming Library (fam module)","is_source":true},{"name":"libglib2.0-0","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-bin","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-data","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-dev","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-dev-bin","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-doc","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-tests","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"},{"name":"libglib2.0-udeb","version":"2.58.1-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.58.1-2ubuntu0.1"}],"disco":[{"name":"glib2.0","version":"2.60.0-1ubuntu0.1","description":"GLib library of C routines","is_source":true},{"name":"libglib2.0-0","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-bin","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-data","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-dev","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-dev-bin","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-doc","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-tests","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"},{"name":"libglib2.0-udeb","version":"2.60.0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.60.0-1ubuntu0.1"}],"xenial":[{"name":"glib2.0","version":"2.48.2-0ubuntu4.2","description":"GLib Input, Output and Streaming Library (fam module)","is_source":true},{"name":"libglib2.0-0","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-0-refdbg","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-bin","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-data","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-dev","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-doc","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-tests","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"},{"name":"libglib2.0-udeb","version":"2.48.2-0ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glib2.0","version_link":"https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-12450"]}]},{"id":"CVE-2019-12449","published":"2019-05-29T00:00:00","updated_at":"2025-08-25T23:03:39.866899+00:00","description":"\nAn issue was discovered in GNOME gvfs 1.29.4 through 1.41.2.\ndaemon/gvfsbackendadmin.c mishandles a file's user and group ownership\nduring move (and copy with G_FILE_COPY_ALL_METADATA) operations from\nadmin:// to file:// URIs, because root privileges are unavailable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4053-1","https://www.cve.org/CVERecord?id=CVE-2019-12449"],"bugs":["https://gitlab.gnome.org/GNOME/gvfs/issues/21","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929755"],"patches":{"gvfs":["upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/d5dfd823c94045488aef8727c553f1e0f7666b90","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/bed1e9685c9f65f6a3ff3b39dd8547db3e7e77f6","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/ec939a01c278d1aaa47153f51b5c5f0887738dd9"]},"tags":{},"packages":[{"name":"gvfs","source":"https://ubuntu.com/security/cve?package=gvfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gvfs","debian":"https://tracker.debian.org/pkg/gvfs","statuses":[{"release_codename":"bionic","status":"released","description":"1.36.1-0ubuntu1.3.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.38.1-0ubuntu1.3.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.40.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4053-1"],"notices":[{"id":"USN-4053-1","title":"GVfs vulnerabilities","summary":"Several security issues were fixed in GVfs.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-07-09T11:29:22.867930","description":"It was discovered that GVfs incorrectly handled the admin backend. Files\ncreated or moved by the admin backend could end up with the wrong ownership\ninformation, contrary to expectations. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-12447, CVE-2019-12448,\nCVE-2019-12449)\n\nIt was discovered that GVfs incorrectly handled authentication on its\nprivate D-Bus socket. A local attacker could possibly connect to this\nsocket and issue D-Bus calls. (CVE-2019-12795)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gvfs","version":"1.36.1-0ubuntu1.3.3","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-backends","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-bin","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-common","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-libs","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"}],"cosmic":[{"name":"gvfs","version":"1.38.1-0ubuntu1.3.2","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-backends","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-bin","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-common","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-daemons","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-fuse","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-libs","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"}],"disco":[{"name":"gvfs","version":"1.40.1-1ubuntu0.1","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-backends","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-bin","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-common","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-daemons","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-fuse","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-libs","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"}],"xenial":[{"name":"gvfs","version":"1.28.2-1ubuntu1~16.04.3","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-backends","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-bin","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-common","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-libs","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-12447","CVE-2019-12448","CVE-2019-12449","CVE-2019-12795"]}]},{"id":"CVE-2019-12448","published":"2019-05-29T00:00:00","updated_at":"2025-08-25T23:03:39.866899+00:00","description":"\nAn issue was discovered in GNOME gvfs 1.29.4 through 1.41.2.\ndaemon/gvfsbackendadmin.c has race conditions because the admin backend\ndoesn't implement query_info_on_read/write.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4053-1","https://www.cve.org/CVERecord?id=CVE-2019-12448"],"bugs":["https://gitlab.gnome.org/GNOME/gvfs/issues/21","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929755"],"patches":{"gvfs":["upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/5cd76d627f4d1982b6e77a0e271ef9301732d09e","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/a1c2e7ecab0d6457fa2227d92e3569c08516eac5","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/464bbc7e4e7fdfc3cb426557562038408b6108c5"]},"tags":{},"packages":[{"name":"gvfs","source":"https://ubuntu.com/security/cve?package=gvfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gvfs","debian":"https://tracker.debian.org/pkg/gvfs","statuses":[{"release_codename":"bionic","status":"released","description":"1.36.1-0ubuntu1.3.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.38.1-0ubuntu1.3.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.40.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4053-1"],"notices":[{"id":"USN-4053-1","title":"GVfs vulnerabilities","summary":"Several security issues were fixed in GVfs.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-07-09T11:29:22.867930","description":"It was discovered that GVfs incorrectly handled the admin backend. Files\ncreated or moved by the admin backend could end up with the wrong ownership\ninformation, contrary to expectations. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-12447, CVE-2019-12448,\nCVE-2019-12449)\n\nIt was discovered that GVfs incorrectly handled authentication on its\nprivate D-Bus socket. A local attacker could possibly connect to this\nsocket and issue D-Bus calls. (CVE-2019-12795)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gvfs","version":"1.36.1-0ubuntu1.3.3","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-backends","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-bin","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-common","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-libs","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"}],"cosmic":[{"name":"gvfs","version":"1.38.1-0ubuntu1.3.2","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-backends","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-bin","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-common","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-daemons","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-fuse","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-libs","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"}],"disco":[{"name":"gvfs","version":"1.40.1-1ubuntu0.1","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-backends","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-bin","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-common","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-daemons","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-fuse","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-libs","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"}],"xenial":[{"name":"gvfs","version":"1.28.2-1ubuntu1~16.04.3","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-backends","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-bin","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-common","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-libs","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-12447","CVE-2019-12448","CVE-2019-12449","CVE-2019-12795"]}]},{"id":"CVE-2019-12447","published":"2019-05-29T00:00:00","updated_at":"2025-08-25T23:03:39.866899+00:00","description":"\nAn issue was discovered in GNOME gvfs 1.29.4 through 1.41.2.\ndaemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not\nused.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4053-1","https://www.cve.org/CVERecord?id=CVE-2019-12447"],"bugs":["https://gitlab.gnome.org/GNOME/gvfs/issues/21","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929755"],"patches":{"gvfs":["upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/daf1163aba229afcfddf0f925aef7e97047e8959","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/3895e09d784ebec0fbc4614d5c37068736120e1d","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/0f25dea30d01d920443ab72b0c254560ec40e14c","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/272e6bdac33309672955e8f8bf1b8f5f1e51fa0a","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/cf2f9c4020bbdd895485244b70e9442a80062cbe","upstream: https://gitlab.gnome.org/GNOME/gvfs/commit/64156459a366d64ab19187455016929b1026189a"]},"tags":{},"packages":[{"name":"gvfs","source":"https://ubuntu.com/security/cve?package=gvfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gvfs","debian":"https://tracker.debian.org/pkg/gvfs","statuses":[{"release_codename":"bionic","status":"released","description":"1.36.1-0ubuntu1.3.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.38.1-0ubuntu1.3.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.40.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4053-1"],"notices":[{"id":"USN-4053-1","title":"GVfs vulnerabilities","summary":"Several security issues were fixed in GVfs.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-07-09T11:29:22.867930","description":"It was discovered that GVfs incorrectly handled the admin backend. Files\ncreated or moved by the admin backend could end up with the wrong ownership\ninformation, contrary to expectations. This issue only affected Ubuntu\n18.04 LTS, Ubuntu 18.10, and Ubuntu 19.04. (CVE-2019-12447, CVE-2019-12448,\nCVE-2019-12449)\n\nIt was discovered that GVfs incorrectly handled authentication on its\nprivate D-Bus socket. A local attacker could possibly connect to this\nsocket and issue D-Bus calls. (CVE-2019-12795)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gvfs","version":"1.36.1-0ubuntu1.3.3","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-backends","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-bin","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-common","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"},{"name":"gvfs-libs","version":"1.36.1-0ubuntu1.3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3.3","pocket":"security"}],"cosmic":[{"name":"gvfs","version":"1.38.1-0ubuntu1.3.2","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-backends","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-bin","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-common","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-daemons","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-fuse","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"},{"name":"gvfs-libs","version":"1.38.1-0ubuntu1.3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.3.2"}],"disco":[{"name":"gvfs","version":"1.40.1-1ubuntu0.1","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-backends","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-bin","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-common","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-daemons","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-fuse","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"},{"name":"gvfs-libs","version":"1.40.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.40.1-1ubuntu0.1"}],"xenial":[{"name":"gvfs","version":"1.28.2-1ubuntu1~16.04.3","description":"Userspace virtual filesystem","is_source":true},{"name":"gvfs","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-backends","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-bin","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-common","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"},{"name":"gvfs-libs","version":"1.28.2-1ubuntu1~16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.28.2-1ubuntu1~16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-12447","CVE-2019-12448","CVE-2019-12449","CVE-2019-12795"]}]},{"id":"CVE-2019-12383","published":"2019-05-28T03:29:00","updated_at":"2025-08-25T23:03:26.252000+00:00","description":"\nTor Browser before 8.0.1 has an information exposure vulnerability. It\nallows remote attackers to detect the browser's UI locale by measuring a\nbutton width, even if the user has a \"Don't send my language\" setting.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"mozjs contains a copy of the SpiderMonkey JavaScript engine"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitweb.torproject.org/tor-browser.git/commit/?id=cbb04b72c68272c2de42f157d40cd7d29a6b7b55","https://hackerone.com/reports/282748","https://trac.torproject.org/projects/tor/ticket/24056","https://www.cve.org/CVERecord?id=CVE-2019-12383"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs60":[],"firefox-esr":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"firefox-esr","source":"https://ubuntu.com/security/cve?package=firefox-esr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox-esr","debian":"https://tracker.debian.org/pkg/firefox-esr","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"mozjs60","source":"https://ubuntu.com/security/cve?package=mozjs60","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs60","debian":"https://tracker.debian.org/pkg/mozjs60","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":49400,"limit":20,"total_results":79316}