{"cves":[{"id":"CVE-2019-9210","published":"2019-02-27T00:00:00","updated_at":"2025-08-25T23:15:53.270088+00:00","description":"\nIn AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer\noverflow upon encountering an invalid PNG size, which results in an\nattempted memcpy to write into a buffer that is too small. (There is also a\nheap-based buffer over-read.)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3936-1","https://ubuntu.com/security/notices/USN-3936-2","https://www.cve.org/CVERecord?id=CVE-2019-9210"],"bugs":["https://sourceforge.net/p/advancemame/bugs/277/","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923416"],"patches":{"advancecomp":["upstream: https://github.com/amadvance/advancecomp/commit/fcf71a89265c78fc26243574dda3a872574a5c02"]},"tags":{},"packages":[{"name":"advancecomp","source":"https://ubuntu.com/security/cve?package=advancecomp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=advancecomp","debian":"https://tracker.debian.org/pkg/advancecomp","statuses":[{"release_codename":"bionic","status":"released","description":"2.1-1ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.1-1ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.1-1ubuntu0.19.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.18-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.20-1ubuntu0.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3936-1","USN-3936-2"],"notices":[{"id":"USN-3936-1","title":"AdvanceCOMP vulnerability","summary":"AdvanceCOMP could be made to run arbitrary code if it opened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-04T14:30:35.520555","description":"It was discovered that AdvanceCOMP incorrectly handled certain PNG files.\nAn attacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"advancecomp","version":"2.1-1ubuntu0.18.04.1","description":"collection of recompression utilities","is_source":true},{"name":"advancecomp","version":"2.1-1ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/advancecomp","version_link":"https://launchpad.net/ubuntu/+source/advancecomp/2.1-1ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"advancecomp","version":"2.1-1ubuntu0.18.10.1","description":"collection of recompression utilities","is_source":true},{"name":"advancecomp","version":"2.1-1ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/advancecomp","version_link":"https://launchpad.net/ubuntu/+source/advancecomp/2.1-1ubuntu0.18.10.1"}],"trusty":[{"name":"advancecomp","version":"1.18-1ubuntu0.2","description":"collection of recompression utilities","is_source":true},{"name":"advancecomp","version":"1.18-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/advancecomp","version_link":"https://launchpad.net/ubuntu/+source/advancecomp/1.18-1ubuntu0.2","pocket":"security"}],"xenial":[{"name":"advancecomp","version":"1.20-1ubuntu0.2","description":"collection of recompression utilities","is_source":true},{"name":"advancecomp","version":"1.20-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/advancecomp","version_link":"https://launchpad.net/ubuntu/+source/advancecomp/1.20-1ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-9210"]},{"id":"USN-3936-2","title":"AdvanceCOMP vulnerability","summary":"AdvanceCOMP could be made to run arbitrary code if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-23T16:17:22.778960","description":"USN-3936-1 fixed a vulnerability in AdvanceCOMP. This update provides\nthe corresponding update for Ubuntu 19.04.\n\nOriginal advisory details:\n\n It was discovered that AdvanceCOMP incorrectly handled certain PNG files.\n An attacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"disco":[{"name":"advancecomp","version":"2.1-1ubuntu0.19.04.1","description":"collection of recompression utilities","is_source":true},{"name":"advancecomp","version":"2.1-1ubuntu0.19.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/advancecomp","version_link":"https://launchpad.net/ubuntu/+source/advancecomp/2.1-1ubuntu0.19.04.1"}]},"type":"USN","cves_ids":["CVE-2019-9210"]}]},{"id":"CVE-2019-9209","published":"2019-02-27T00:00:00","updated_at":"2025-08-25T23:15:53.270088+00:00","description":"\nIn Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related\ndissectors could crash. This was addressed in epan/dissectors/packet-ber.c\nby preventing a buffer overflow associated with excessive digits in time\nvalues.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15447","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=f8fbe9f934d65b2694fa74622e5eb2e1dc8cd20b","https://www.wireshark.org/security/wnpa-sec-2019-06.html","https://ubuntu.com/security/notices/USN-3986-1","https://www.cve.org/CVERecord?id=CVE-2019-9209"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923611"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.8-1~ubuntu18.04.0","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.6.8-1~ubuntu18.10.0","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.8-1~ubuntu14.04.0~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"2.6.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.8-1~ubuntu16.04.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-3986-1"],"notices":[{"id":"USN-3986-1","title":"Wireshark vulnerabilities","summary":"Wireshark could be made to crash if it received specially crafted network\ntraffic or input files.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-05-16T15:29:24.241024","description":"It was discovered that Wireshark improperly handled certain input. A remote or\nlocal attacker could cause Wireshark to crash by injecting malform packets onto\nthe wire or convincing someone to read a malformed packet trace file.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"wireshark","version":"2.6.8-1~ubuntu18.04.0","description":"network traffic analyzer","is_source":true},{"name":"libwireshark-data","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwireshark-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwireshark11","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwiretap-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwiretap8","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwscodecs2","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwsutil-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwsutil9","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"tshark","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-common","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-doc","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-gtk","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-qt","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"}],"cosmic":[{"name":"wireshark","version":"2.6.8-1~ubuntu18.10.0","description":"network traffic analyzer","is_source":true},{"name":"libwireshark-data","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwireshark-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwireshark11","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwiretap-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwiretap8","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwscodecs2","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwsutil-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwsutil9","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"tshark","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-common","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-doc","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-gtk","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-qt","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"}],"xenial":[{"name":"wireshark","version":"2.6.8-1~ubuntu16.04.0","description":"network traffic analyzer","is_source":true},{"name":"libwireshark-data","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwireshark-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwireshark11","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwiretap-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwiretap8","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwscodecs2","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwsutil-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwsutil9","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"tshark","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-common","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-doc","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-gtk","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-qt","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-10894","CVE-2019-10895","CVE-2019-10896","CVE-2019-10899","CVE-2019-10901","CVE-2019-10903","CVE-2019-9208","CVE-2019-9209","CVE-2019-9214"]}]},{"id":"CVE-2019-9208","published":"2019-02-27T00:00:00","updated_at":"2025-08-25T23:15:53.270088+00:00","description":"\nIn Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the TCAP dissector could\ncrash. This was addressed in epan/dissectors/asn1/tcap/tcap.cnf by avoiding\nNULL pointer dereferences.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=15464","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=3d1b8004ed3a07422ca5d4e4ee8097150b934fd2","https://www.wireshark.org/security/wnpa-sec-2019-07.html","https://ubuntu.com/security/notices/USN-3986-1","https://www.cve.org/CVERecord?id=CVE-2019-9208"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=923611"],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"disco","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.8-1~ubuntu18.04.0","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.6.8-1~ubuntu18.10.0","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.6.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.8-1~ubuntu14.04.0~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"2.6.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.8-1~ubuntu16.04.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-3986-1"],"notices":[{"id":"USN-3986-1","title":"Wireshark vulnerabilities","summary":"Wireshark could be made to crash if it received specially crafted network\ntraffic or input files.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-05-16T15:29:24.241024","description":"It was discovered that Wireshark improperly handled certain input. A remote or\nlocal attacker could cause Wireshark to crash by injecting malform packets onto\nthe wire or convincing someone to read a malformed packet trace file.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"wireshark","version":"2.6.8-1~ubuntu18.04.0","description":"network traffic analyzer","is_source":true},{"name":"libwireshark-data","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwireshark-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwireshark11","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwiretap-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwiretap8","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwscodecs2","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwsutil-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"libwsutil9","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"tshark","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-common","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-dev","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-doc","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-gtk","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"},{"name":"wireshark-qt","version":"2.6.8-1~ubuntu18.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.04.0","pocket":"security"}],"cosmic":[{"name":"wireshark","version":"2.6.8-1~ubuntu18.10.0","description":"network traffic analyzer","is_source":true},{"name":"libwireshark-data","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwireshark-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwireshark11","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwiretap-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwiretap8","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwscodecs2","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwsutil-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"libwsutil9","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"tshark","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-common","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-dev","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-doc","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-gtk","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"},{"name":"wireshark-qt","version":"2.6.8-1~ubuntu18.10.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu18.10.0"}],"xenial":[{"name":"wireshark","version":"2.6.8-1~ubuntu16.04.0","description":"network traffic analyzer","is_source":true},{"name":"libwireshark-data","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwireshark-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwireshark11","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwiretap-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwiretap8","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwscodecs2","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwsutil-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"libwsutil9","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"tshark","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-common","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-dev","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-doc","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-gtk","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"},{"name":"wireshark-qt","version":"2.6.8-1~ubuntu16.04.0","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":"https://launchpad.net/ubuntu/+source/wireshark/2.6.8-1~ubuntu16.04.0","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-10894","CVE-2019-10895","CVE-2019-10896","CVE-2019-10899","CVE-2019-10901","CVE-2019-10903","CVE-2019-9208","CVE-2019-9209","CVE-2019-9214"]}]},{"id":"CVE-2019-3840","published":"2019-02-27T00:00:00","updated_at":"2025-08-25T23:11:54.853340+00:00","description":"\nA NULL pointer dereference flaw was discovered in libvirt before version\n5.0.0 in the way it gets interface information through the QEMU agent. An\nattacker in a guest VM can use this flaw to crash libvirtd and cause a\ndenial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.2.14"}],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.redhat.com/archives/libvir-list/2019-January/msg00241.html","https://ubuntu.com/security/notices/USN-3909-1","https://www.cve.org/CVERecord?id=CVE-2019-3840"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1663051"],"patches":{"libvirt":["upstream: https://libvirt.org/git/?p=libvirt.git;a=commit;h=7cfd1fbb1332ae5df678b9f41a62156cb2e88c73"]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"bionic","status":"released","description":"4.0.0-1ubuntu8.8","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.6.0-2ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.1-1ubuntu10.25","component":null,"pocket":"security"}]}],"notices_ids":["USN-3909-1"],"notices":[{"id":"USN-3909-1","title":"libvirt vulnerability","summary":"libvirt could be made to crash under certain conditions.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2019-03-14T17:53:47.894836","description":"It was discovered that libvirt incorrectly handled waiting for certain\nagent events. An attacker inside a guest could possibly use this issue to\ncause libvirtd to stop responding, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libvirt","version":"4.0.0-1ubuntu8.8","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libnss-libvirt","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-bin","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-clients","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-daemon","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-daemon-driver-storage-gluster","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-daemon-driver-storage-rbd","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-daemon-driver-storage-sheepdog","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-daemon-driver-storage-zfs","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-daemon-system","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-dev","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-doc","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-sanlock","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt-wireshark","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"},{"name":"libvirt0","version":"4.0.0-1ubuntu8.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.0.0-1ubuntu8.8","pocket":"security"}],"cosmic":[{"name":"libvirt","version":"4.6.0-2ubuntu3.4","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libnss-libvirt","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-clients","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-daemon","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-daemon-driver-storage-gluster","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-daemon-driver-storage-rbd","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-daemon-driver-storage-sheepdog","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-daemon-driver-storage-zfs","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-daemon-system","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-dev","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-doc","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-sanlock","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt-wireshark","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"},{"name":"libvirt0","version":"4.6.0-2ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/4.6.0-2ubuntu3.4"}],"xenial":[{"name":"libvirt","version":"1.3.1-1ubuntu10.25","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"1.3.1-1ubuntu10.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.25","pocket":"security"},{"name":"libvirt-dev","version":"1.3.1-1ubuntu10.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.25","pocket":"security"},{"name":"libvirt-doc","version":"1.3.1-1ubuntu10.25","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.25","pocket":"security"},{"name":"libvirt0","version":"1.3.1-1ubuntu10.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.25","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-3840"]}]},{"id":"CVE-2019-9199","published":"2019-02-26T23:29:00","updated_at":"2025-08-26T12:17:44.069490+00:00","description":"\nPoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo\n0.9.6 has a NULL pointer dereference that can (for example) be triggered by\nsending a crafted PDF file to the podofoimpose binary. It allows an\nattacker to cause Denial of Service (Segmentation fault) or possibly have\nunspecified other impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-setsource-podofo-0-9-6-trunk-r1967/","https://sourceforge.net/p/podofo/tickets/40/","https://www.cve.org/CVERecord?id=CVE-2019-9199"],"bugs":[""],"patches":{"libpodofo":[]},"tags":{},"packages":[{"name":"libpodofo","source":"https://ubuntu.com/security/cve?package=libpodofo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libpodofo","debian":"https://tracker.debian.org/pkg/libpodofo","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.6+dfsg-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9192","published":"2019-02-26T18:29:00","updated_at":"2025-08-04T19:34:53.243538+00:00","description":"\nIn the GNU C Library (aka glibc or libc6) through 2.29,\ncheck_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,\nas demonstrated by '(|)(\\\\1\\\\1)*' in grep, a different issue than\nCVE-2018-20796. NOTE: the software maintainer disputes that this is a\nvulnerability because the behavior occurs only with a crafted pattern","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream does not consider this to be a security issue, per\nhttps://sourceware.org/glibc/wiki/Security%20Exceptions\n\nas of 2019-07-29, no fix available\nThis issue has been disputed, marking as not-affected"}],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2019-9192"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=24269"],"patches":{"eglibc":[],"glibc":[]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9169","published":"2019-02-26T02:29:00","updated_at":"2025-08-25T23:15:44.153788+00:00","description":"\nIn the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node\nin posix/regexec.c has a heap-based buffer over-read via an attempted\ncase-insensitive regular-expression match.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4416-1","https://www.cve.org/CVERecord?id=CVE-2019-9169"],"bugs":["https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34140","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34142","https://sourceware.org/bugzilla/show_bug.cgi?id=24114"],"patches":{"eglibc":["upstream: https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=583dd860d5b833037175247230a328f0050dbfe9;hp=2bac7daa58da1a313bd452369b0508b31e146637"],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=583dd860d5b833037175247230a328f0050dbfe9","upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=4d0b1b0f61bfba034e9e76a1d76acc59c975238f","upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=2aee101ff6075dd97a99982a1ba29e21ec25c52f"]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"bionic","status":"released","description":"2.27-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.30-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.30-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.30","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.23-0ubuntu11.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4416-1"],"notices":[{"id":"USN-4416-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2020-07-06T18:10:11.630219","description":"Florian Weimer discovered that the GNU C Library incorrectly handled\ncertain memory operations. A remote attacker could use this issue to cause\nthe GNU C Library to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2017-12133)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nSSE2-optimized memmove operations. A remote attacker could use this issue\nto cause the GNU C Library to crash, resulting in a denial of service, or\npossibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2017-18269)\n\nIt was discovered that the GNU C Library incorrectly handled certain\npathname operations. A remote attacker could use this issue to cause the\nGNU C Library to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2018-11236)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nAVX-512-optimized mempcpy operations. A remote attacker could use this\nissue to cause the GNU C Library to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. This issue only affected\nUbuntu 18.04 LTS. (CVE-2018-11237)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nhostname loookups. A remote attacker could use this issue to cause the GNU\nC Library to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19591)\n\nJakub Wilk discovered that the GNU C Library incorrectly handled certain\nmemalign functions. A remote attacker could use this issue to cause the GNU\nC Library to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-6485)\n\nIt was discovered that the GNU C Library incorrectly ignored the\nLD_PREFER_MAP_32BIT_EXEC environment variable after security transitions. A\nlocal attacker could use this issue to bypass ASLR restrictions.\n(CVE-2019-19126)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nregular expressions. A remote attacker could possibly use this issue to\ncause the GNU C Library to crash, resulting in a denial of service. This\nissue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-9169)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nbit patterns. A remote attacker could use this issue to cause the GNU C\nLibrary to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04\nLTS. (CVE-2020-10029)\n\nIt was discovered that the GNU C Library incorrectly handled certain\nsignal trampolines on PowerPC. A remote attacker could use this issue to\ncause the GNU C Library to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2020-1751)\n\nIt was discovered that the GNU C Library incorrectly handled tilde\nexpansion. A remote attacker could use this issue to cause the GNU C\nLibrary to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2020-1752)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"glibc","version":"2.27-3ubuntu1.2","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"glibc-source","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc-bin","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc-dev-bin","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-amd64","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-armel","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-armel","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-i386","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-s390","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-dev-x32","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-i386","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-pic","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-s390","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-udeb","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"libc6-x32","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"locales","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"locales-all","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"multiarch-support","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"},{"name":"nscd","version":"2.27-3ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.27-3ubuntu1.2","pocket":"security"}],"eoan":[{"name":"glibc","version":"2.30-0ubuntu2.2","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"glibc-source","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc-bin","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc-dev-bin","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-amd64","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-armel","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-amd64","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-armel","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-i386","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-s390","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-dev-x32","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-i386","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-pic","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-s390","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-udeb","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"libc6-x32","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"locales","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"locales-all","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"},{"name":"nscd","version":"2.30-0ubuntu2.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.30-0ubuntu2.2"}],"xenial":[{"name":"glibc","version":"2.23-0ubuntu11.2","description":"GNU C Library","is_source":true},{"name":"glibc-doc","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-i386","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu11.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12133","CVE-2017-18269","CVE-2018-11236","CVE-2018-11237","CVE-2018-19591","CVE-2018-6485","CVE-2019-19126","CVE-2019-9169","CVE-2020-10029","CVE-2020-1751","CVE-2020-1752"]}]},{"id":"CVE-2018-20796","published":"2019-02-26T02:29:00","updated_at":"2025-08-25T22:53:07.430273+00:00","description":"\nIn the GNU C Library (aka glibc or libc6) through 2.29,\ncheck_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,\nas demonstrated by '(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+' in grep.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"glibc regex compiler is not supposed to be exposed to untrusted\ncontent, and upstream does not consider this to be a security\nissue: https://sourceware.org/glibc/wiki/Security%20Exceptions\nhttps://lists.gnu.org/r/bug-gnulib/2018-09/msg00068.html\n\nas of 2020-06-04, no fix available from upstream.\nWe will not be fixing this issue in Ubuntu, marking as\nignored."}],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/bug-gnulib/2019-01/msg00108.html","https://www.cve.org/CVERecord?id=CVE-2018-20796"],"bugs":["https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34141"],"patches":{"eglibc":[],"glibc":[]},"tags":{},"packages":[{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-5155","published":"2019-02-26T02:29:00","updated_at":"2025-08-18T16:38:47.798682+00:00","description":"\nIn the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in\nposix/regcomp.c misparses alternatives, which allows attackers to cause a\ndenial of service (assertion failure and application exit) or trigger an\nincorrect result by attempting a regular-expression match.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4954-1","https://www.cve.org/CVERecord?id=CVE-2009-5155"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=11053","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22793","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=32806","https://debbugs.gnu.org/cgi/bugreport.cgi?bug=34238","https://sourceware.org/bugzilla/show_bug.cgi?id=18986"],"patches":{"eglibc":[],"glibc":["upstream: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=eb04c21373e2a2885f3d52ff192b0499afe3c672","suse: https://build.opensuse.org/package/view_file/SUSE:SLE-12-SP5:GA/glibc/regex-parse-reg-exp.patch?expand=1","upstream: http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272"],"gnulib":["upstream: http://git.savannah.gnu.org/cgit/gnulib.git/commit/?id=5513b40999149090987a0341c018d05d3eea1272"]},"tags":{},"packages":[{"name":"gnulib","source":"https://ubuntu.com/security/cve?package=gnulib","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnulib","debian":"https://tracker.debian.org/pkg/gnulib","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20140202+stable-3.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"20140202+stable-4","component":null,"pocket":"security"}]},{"name":"eglibc","source":"https://ubuntu.com/security/cve?package=eglibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=eglibc","debian":"https://tracker.debian.org/pkg/eglibc","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"glibc","source":"https://ubuntu.com/security/cve?package=glibc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=glibc","debian":"https://tracker.debian.org/pkg/glibc","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.23-0ubuntu11.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.28-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.28-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4954-1"],"notices":[{"id":"USN-4954-1","title":"GNU C Library vulnerabilities","summary":"Several security issues were fixed in GNU C Library.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2021-05-14T00:19:34.222269","description":"Jason Royes and Samuel Dytrych discovered that the memcpy()\nimplementation for 32 bit ARM processors in the GNU C Library contained\nan integer underflow vulnerability. An attacker could possibly use\nthis to cause a denial of service (application crash) or execute\narbitrary code. (CVE-2020-6096)\n\nIt was discovered that the POSIX regex implementation in the GNU C\nLibrary did not properly parse alternatives. An attacker could use this\nto cause a denial of service. (CVE-2009-5155)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"glibc","version":"2.23-0ubuntu11.3","description":"GNU C Library","is_source":true},{"name":"libc6-i386","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-ppc64","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev-s390","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"glibc-source","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc-bin","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-x32","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-s390","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-armel","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-pic","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev-ppc64","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev-armel","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"glibc-doc","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"multiarch-support","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-amd64","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev-amd64","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"locales-all","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev-x32","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"locales","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-udeb","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc6-dev-i386","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"libc-dev-bin","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"},{"name":"nscd","version":"2.23-0ubuntu11.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/glibc","version_link":"https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu11.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2009-5155","CVE-2020-6096"]}]},{"id":"CVE-2019-9200","published":"2019-02-26T00:00:00","updated_at":"2025-08-25T23:15:53.270088+00:00","description":"\nA heap-based buffer underwrite exists in ImageStream::getLine() located at\nStream.cc in Poppler 0.74.0 that can (for example) be triggered by sending\na crafted PDF file to the pdfimages binary. It allows an attacker to cause\nDenial of Service (Segmentation fault) or possibly have unspecified other\nimpact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://research.loginsoft.com/bugs/heap-based-buffer-underwrite-in-imagestreamgetline-poppler-0-74-0/","https://ubuntu.com/security/notices/USN-3905-1","https://ubuntu.com/security/notices/USN-4042-1","https://www.cve.org/CVERecord?id=CVE-2019-9200"],"bugs":["https://gitlab.freedesktop.org/poppler/poppler/issues/728"],"patches":{"poppler":["upstream: https://gitlab.freedesktop.org/poppler/poppler/commit/f4136a6353162db249f63ddb0f20611622ab61b4"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"bionic","status":"released","description":"0.62.0-2ubuntu2.8","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.68.0-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.74.0-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.17","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.13","component":null,"pocket":"security"}]}],"notices_ids":["USN-4042-1","USN-3905-1"],"notices":[{"id":"USN-4042-1","title":"poppler vulnerabilities","summary":"Several security issues were fixed in poppler.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-06-27T13:29:23.845161","description":"It was discovered that poppler incorrectly handled certain files. If a user\nor automated system were tricked into opening a crafted PDF file, an\nattacker could cause a denial of service, or possibly execute arbitrary\ncode\n","is_hidden":false,"release_packages":{"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.9","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"}],"cosmic":[{"name":"poppler","version":"0.68.0-0ubuntu1.7","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-cpp-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-cpp0v5","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-glib-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-glib-doc","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-glib8","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-private-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-qt5-1","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-qt5-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler79","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"poppler-utils","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"}],"disco":[{"name":"poppler","version":"0.74.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-cpp-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-cpp0v5","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-glib-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-glib-doc","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-glib8","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-private-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-qt5-1","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-qt5-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler85","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"poppler-utils","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.14","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-9865","CVE-2018-18897","CVE-2018-20662","CVE-2019-10018","CVE-2019-10019","CVE-2019-10021","CVE-2019-10023","CVE-2019-10872","CVE-2019-10873","CVE-2019-12293","CVE-2019-9200","CVE-2019-9631","CVE-2019-9903"]},{"id":"USN-3905-1","title":"poppler vulnerability","summary":"poppler could be made to crash if it opened a specially crafted\nfile.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-03-11T11:58:37.807818","description":"It was discovered that poppler incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.8","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.8","pocket":"security"}],"cosmic":[{"name":"poppler","version":"0.68.0-0ubuntu1.6","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-cpp-dev","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-cpp0v5","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-dev","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-glib-dev","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-glib-doc","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-glib8","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-private-dev","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-qt5-1","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler-qt5-dev","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"libpoppler79","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"},{"name":"poppler-utils","version":"0.68.0-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.6"}],"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.17","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.17","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.13","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.13","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-9200"]}]},{"id":"CVE-2019-1559","published":"2019-02-26T00:00:00","updated_at":"2025-08-25T23:06:51.836945+00:00","description":"\nIf an application encounters a fatal protocol error and then calls\nSSL_shutdown() twice (once to send a close_notify, and once to receive one)\nthen OpenSSL can respond differently to the calling application if a 0 byte\nrecord is received with invalid padding compared to if a 0 byte record is\nreceived with an invalid MAC. If the application then behaves differently\nbased on that in a way that is detectable to the remote peer, then this\namounts to a padding oracle that could be used to decrypt data. In order\nfor this to be exploitable \"non-stitched\" ciphersuites must be in use.\nStitched ciphersuites are optimised implementations of certain commonly\nused ciphersuites. Also the application must call SSL_shutdown() twice even\nif a protocol error has occurred (applications should not do this but some\ndo anyway). Fixed in OpenSSL 1.0.2r (Affected 1.0.2-1.0.2q).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"doesn't affect 1.1.x\n\nthis fix is a workaround for applications that call\nSSL_shutdown() twice even if a protocol error has occurred\n\nupstream fix uses error handling mechanism introduced in 1.0.2,\nwhich isn't available in 1.0.1f. While we are unlikely to fix\nthis issue in Ubuntu 14.04 LTS, marking as deferred for now\nin case the vulnerable applications are identified."}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.openssl.org/news/secadv/20190226.txt","https://github.com/RUB-NDS/TLS-Padding-Oracles","https://ubuntu.com/security/notices/USN-3899-1","https://ubuntu.com/security/notices/USN-4376-2","https://www.cve.org/CVERecord?id=CVE-2019-1559"],"bugs":[""],"patches":{"openssl":["upstream: https://github.com/openssl/openssl/commit/e9bbefbf0f24c57645e7ad6a5a71ae649d18ac8e"],"openssl098":[],"openssl1.0":[],"nodejs":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"bionic","status":"not-affected","description":"uses system openssl1.0","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"uses system openssl1.0","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"uses system openssl1.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"uses system openssl1.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"bionic","status":"not-affected","description":"1.1.0g-2ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.1.1-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.1.1a-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.1.1a-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.1.1a-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.27+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.15","component":null,"pocket":"security"}]},{"name":"openssl098","source":"https://ubuntu.com/security/cve?package=openssl098","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl098","debian":"https://tracker.debian.org/pkg/openssl098","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2n-1ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.2n-1ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3899-1","USN-4376-2"],"notices":[{"id":"USN-3899-1","title":"OpenSSL vulnerability","summary":"OpenSSL could be made to expose sensitive information over the network.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2019-02-27T17:23:00.430653","description":"Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain\napplications incorrectly used OpenSSL and could be exposed to a padding\noracle attack. A remote attacker could possibly use this issue to decrypt\ndata.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.3","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libcrypto1.0.0-udeb","version":"1.0.2n-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.3","pocket":"security"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.3","pocket":"security"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.3","pocket":"security"},{"name":"libssl1.0.0-udeb","version":"1.0.2n-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.3","pocket":"security"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu5.3","pocket":"security"}],"cosmic":[{"name":"openssl1.0","version":"1.0.2n-1ubuntu6.2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libcrypto1.0.0-udeb","version":"1.0.2n-1ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu6.2"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu6.2"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu6.2"},{"name":"libssl1.0.0-udeb","version":"1.0.2n-1ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu6.2"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":"https://launchpad.net/ubuntu/+source/openssl1.0/1.0.2n-1ubuntu6.2"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libcrypto1.0.0-udeb","version":"1.0.2g-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.15","pocket":"security"},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.15","pocket":"security"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.15","pocket":"security"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.15","pocket":"security"},{"name":"libssl1.0.0-udeb","version":"1.0.2g-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.15","pocket":"security"},{"name":"openssl","version":"1.0.2g-1ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.2g-1ubuntu4.15","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-1559"]},{"id":"USN-4376-2","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2020-07-09T17:41:10.449098","description":"USN-4376-1 fixed several vulnerabilities in OpenSSL. This update provides\nthe corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n Cesar Pereida García, Sohaib ul Hassan, Nicola Tuveri, Iaroslav Gridin,\n Alejandro Cabrera Aldaya, and Billy Brumley discovered that OpenSSL\n incorrectly handled ECDSA signatures. An attacker could possibly use this\n issue to perform a timing side-channel attack and recover private ECDSA\n keys. (CVE-2019-1547)\n\n Juraj Somorovsky, Robert Merget, and Nimrod Aviram discovered that certain\n applications incorrectly used OpenSSL and could be exposed to a padding\n oracle attack. A remote attacker could possibly use this issue to decrypt\n data. (CVE-2019-1559)\n\n Bernd Edlinger discovered that OpenSSL incorrectly handled certain\n decryption functions. In certain scenarios, a remote attacker could\n possibly use this issue to perform a padding oracle attack and decrypt\n traffic. (CVE-2019-1563)\n","is_hidden":false,"release_packages":{"precise":[{"name":"openssl","version":"1.0.1-4ubuntu5.44","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.1-4ubuntu5.44","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.44"},{"name":"libssl-dev","version":"1.0.1-4ubuntu5.44","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.44"},{"name":"openssl","version":"1.0.1-4ubuntu5.44","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.44"},{"name":"libssl-doc","version":"1.0.1-4ubuntu5.44","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.44"},{"name":"libcrypto1.0.0-udeb","version":"1.0.1-4ubuntu5.44","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.44"},{"name":"libssl1.0.0-udeb","version":"1.0.1-4ubuntu5.44","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.44"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm1","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.27+esm1"},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.27+esm1"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.27+esm1"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.27+esm1"},{"name":"libcrypto1.0.0-udeb","version":"1.0.1f-1ubuntu2.27+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.27+esm1"},{"name":"libssl1.0.0-udeb","version":"1.0.1f-1ubuntu2.27+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.27+esm1"}]},"type":"USN","cves_ids":["CVE-2019-1547","CVE-2019-1559","CVE-2019-1563"]}]},{"id":"CVE-2019-9152","published":"2019-02-25T19:29:00","updated_at":"2026-02-27T14:44:30.393773+00:00","description":"\nAn issue was discovered in the HDF HDF5 1.10.4 library. There is an out of\nbounds read in the function H5MM_xstrdup in H5MM.c when called from\nH5O_dtype_decode_helper in H5Odtype.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/magicSwordsMan/PAAFS/tree/master/vul8","https://www.cve.org/CVERecord?id=CVE-2019-9152"],"bugs":[""],"patches":{"hdf5":["upstream: https://github.com/HDFGroup/hdf5/commit/0f94940f1a9ae95de38b70709eb413511b76c73b"]},"tags":{},"packages":[{"name":"hdf5","source":"https://ubuntu.com/security/cve?package=hdf5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hdf5","debian":"https://tracker.debian.org/pkg/hdf5","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.14.0","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9151","published":"2019-02-25T19:29:00","updated_at":"2026-02-27T14:45:02.790268+00:00","description":"\nAn issue was discovered in the HDF HDF5 1.10.4 library. There is an out of\nbounds read in the function H5VM_memcpyvv in H5VM.c when called from\nH5D__compact_readvv in H5Dcompact.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/magicSwordsMan/PAAFS/tree/master/vul7","https://www.cve.org/CVERecord?id=CVE-2019-9151"],"bugs":[""],"patches":{"hdf5":["upstream: https://github.com/HDFGroup/hdf5/commit/dafc7285bb1df4a6529a64c215c5de4017016d24"]},"tags":{},"packages":[{"name":"hdf5","source":"https://ubuntu.com/security/cve?package=hdf5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hdf5","debian":"https://tracker.debian.org/pkg/hdf5","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.14.0","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9144","published":"2019-02-25T15:29:00","updated_at":"2025-08-25T23:15:44.153788+00:00","description":"\nAn issue was discovered in Exiv2 0.27. There is infinite recursion at\nBigTiffImage::printIFD in the file bigtiffimage.cpp. This can be triggered\nby a crafted file. It allows an attacker to cause Denial of Service\n(Segmentation fault) or possibly have unspecified other impact.","ubuntu_description":"","notes":[{"author":"leosilva","note":"same as CVE-2019-9143, issue introduced in 0.27."}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Exiv2/exiv2/issues/712","https://research.loginsoft.com/bugs/uncontrolled-recursion-loop-in-exiv2anonymous-namespacebigtiffimageprintifd-exiv2-0-27/","https://www.cve.org/CVERecord?id=CVE-2019-9144"],"bugs":[""],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9143","published":"2019-02-25T15:29:00","updated_at":"2025-08-25T23:15:44.153788+00:00","description":"\nAn issue was discovered in Exiv2 0.27. There is infinite recursion at\nExiv2::Image::printTiffStructure in the file image.cpp. This can be\ntriggered by a crafted file. It allows an attacker to cause Denial of\nService (Segmentation fault) or possibly have unspecified other impact.","ubuntu_description":"","notes":[{"author":"leosilva","note":"issue was introduced in 0.27."}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Exiv2/exiv2/issues/711","https://research.loginsoft.com/bugs/uncontrolled-recursion-loop-in-exiv2imageprinttiffstructure-exiv2-0-27/","https://www.cve.org/CVERecord?id=CVE-2019-9143"],"bugs":[""],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-3824","published":"2019-02-25T09:00:00","updated_at":"2025-08-25T23:11:50.307945+00:00","description":"\nA flaw was found in the way an LDAP search expression could crash the\nshared LDAP server process of a samba AD DC in samba before version 4.10.\nAn authenticated user, having read permissions on the LDAP server, could\nuse this flaw to cause denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3895-1","https://www.cve.org/CVERecord?id=CVE-2019-3824"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=13773"],"patches":{"ldb":[]},"tags":{},"packages":[{"name":"ldb","source":"https://ubuntu.com/security/cve?package=ldb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ldb","debian":"https://tracker.debian.org/pkg/ldb","statuses":[{"release_codename":"bionic","status":"released","description":"2:1.2.3-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2:1.4.0+really1.3.5-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.1.24-0ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:1.1.24-1ubuntu3.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3895-1"],"notices":[{"id":"USN-3895-1","title":"LDB vulnerability","summary":"LDB could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2019-02-26T14:26:20.616219","description":"It was discovered that LDB incorrectly handled certain search expressions.\nA remote attacker could possibly use this issue to cause the Samba LDAP\nprocess to crash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ldb","version":"2:1.2.3-1ubuntu0.1","description":"LDAP-like embedded database - tools","is_source":true},{"name":"ldb-tools","version":"2:1.2.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.2.3-1ubuntu0.1","pocket":"security"},{"name":"libldb-dev","version":"2:1.2.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.2.3-1ubuntu0.1","pocket":"security"},{"name":"libldb1","version":"2:1.2.3-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.2.3-1ubuntu0.1","pocket":"security"},{"name":"python-ldb","version":"2:1.2.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.2.3-1ubuntu0.1","pocket":"security"},{"name":"python-ldb-dev","version":"2:1.2.3-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.2.3-1ubuntu0.1","pocket":"security"}],"cosmic":[{"name":"ldb","version":"2:1.4.0+really1.3.5-2ubuntu0.1","description":"LDAP-like embedded database - tools","is_source":true},{"name":"ldb-tools","version":"2:1.4.0+really1.3.5-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.4.0+really1.3.5-2ubuntu0.1"},{"name":"libldb-dev","version":"2:1.4.0+really1.3.5-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.4.0+really1.3.5-2ubuntu0.1"},{"name":"libldb1","version":"2:1.4.0+really1.3.5-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.4.0+really1.3.5-2ubuntu0.1"},{"name":"python-ldb","version":"2:1.4.0+really1.3.5-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.4.0+really1.3.5-2ubuntu0.1"},{"name":"python-ldb-dev","version":"2:1.4.0+really1.3.5-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.4.0+really1.3.5-2ubuntu0.1"}],"trusty":[{"name":"ldb","version":"1:1.1.24-0ubuntu0.14.04.2","description":"LDAP-like embedded database - tools","is_source":true},{"name":"ldb-tools","version":"1:1.1.24-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/1:1.1.24-0ubuntu0.14.04.2","pocket":"security"},{"name":"libldb-dev","version":"1:1.1.24-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/1:1.1.24-0ubuntu0.14.04.2","pocket":"security"},{"name":"libldb1","version":"1:1.1.24-0ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/1:1.1.24-0ubuntu0.14.04.2","pocket":"security"},{"name":"python-ldb","version":"1:1.1.24-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/1:1.1.24-0ubuntu0.14.04.2","pocket":"security"},{"name":"python-ldb-dev","version":"1:1.1.24-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/1:1.1.24-0ubuntu0.14.04.2","pocket":"security"}],"xenial":[{"name":"ldb","version":"2:1.1.24-1ubuntu3.1","description":"LDAP-like embedded database - tools","is_source":true},{"name":"ldb-tools","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"},{"name":"libldb-dev","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"},{"name":"libldb1","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"},{"name":"python-ldb","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"},{"name":"python-ldb-dev","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"},{"name":"python3-ldb","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"},{"name":"python3-ldb-dev","version":"2:1.1.24-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ldb","version_link":"https://launchpad.net/ubuntu/+source/ldb/2:1.1.24-1ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-3824"]}]},{"id":"CVE-2019-9114","published":"2019-02-25T04:29:00","updated_at":"2025-08-26T12:17:44.069490+00:00","description":"\nMing (aka libming) 0.4.8 has an out of bounds write vulnerability in the\nfunction strcpyext() in the decompile.c file in libutil.a.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/libming/libming/issues/170","https://www.cve.org/CVERecord?id=CVE-2019-9114"],"bugs":[""],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9113","published":"2019-02-25T04:29:00","updated_at":"2025-08-26T12:17:44.069490+00:00","description":"\nMing (aka libming) 0.4.8 has a NULL pointer dereference in the function\ngetString() in the decompile.c file in libutil.a.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/libming/libming/issues/171","https://www.cve.org/CVERecord?id=CVE-2019-9113"],"bugs":[""],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-9162","published":"2019-02-25T00:00:00","updated_at":"2026-07-04T07:48:41.002797+00:00","description":"\nIn the Linux kernel before 4.20.12,\nnet/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has\ninsufficient ASN.1 length checks (aka an array index error), making\nout-of-bounds read and write operations possible, leading to an OOPS or\nlocal privilege escalation. This affects snmp_version and snmp_helper.","ubuntu_description":"\nJann Horn discovered that the SNMP NAT implementation in the Linux kernel\nperformed insufficient ASN.1 length checks. An attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode.","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc","https://ubuntu.com/security/notices/USN-3930-1","https://ubuntu.com/security/notices/USN-3930-2","https://www.cve.org/CVERecord?id=CVE-2019-9162"],"bugs":["https://bugs.chromium.org/p/project-zero/issues/detail?id=1776"],"patches":{"linux":["break-fix: cc2d58634e0f489d28b5564c05abc69930b4d920 c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-gcp-edge":[],"linux-aws-hwe":[],"linux-oracle":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-17.18","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1012.14","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1030.31~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"released","description":"4.18.0-1014.14~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1014.14","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1009.9","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.18.0-1014.14~18.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1009.9","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1008.9","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"bionic","status":"released","description":"4.18.0-1008.9~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"released","description":"4.18.0-17.18~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.0.0-8.9~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1009.9","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1004.9","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1007.9","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1007.9~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1011.13","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0~rc7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"}]}],"notices_ids":["USN-3930-2","USN-3930-1"],"notices":[{"id":"USN-3930-2","title":"Linux kernel (HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-04-02T18:36:10.430823","description":"USN-3930-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.10.\nThis update provides the corresponding updates for the Linux Hardware\nEnablement (HWE) kernel from Ubuntu 18.10 for Ubuntu 18.04 LTS.\n\nMathias Payer and Hui Peng discovered a use-after-free vulnerability in the\nAdvanced Linux Sound Architecture (ALSA) subsystem. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-19824)\n\nShlomi Oberman, Yuli Shapiro, and Ran Menscher discovered an information\nleak in the Bluetooth implementation of the Linux kernel. An attacker\nwithin Bluetooth range could use this to expose sensitive information\n(kernel memory). (CVE-2019-3459, CVE-2019-3460)\n\nJann Horn discovered that the KVM implementation in the Linux kernel\ncontained a use-after-free vulnerability. An attacker in a guest VM with\naccess to /dev/kvm could use this to cause a denial of service (guest VM\ncrash). (CVE-2019-6974)\n\nJim Mattson and Felix Wilhelm discovered a use-after-free vulnerability in\nthe KVM subsystem of the Linux kernel, when using nested virtual machines.\nA local attacker in a guest VM could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code in the host system.\n(CVE-2019-7221)\n\nFelix Wilhelm discovered that an information leak vulnerability existed in\nthe KVM subsystem of the Linux kernel, when nested virtualization is used.\nA local attacker could use this to expose sensitive information (host\nsystem memory to a guest VM). (CVE-2019-7222)\n\nJann Horn discovered that the eBPF implementation in the Linux kernel was\ninsufficiently hardened against Spectre V1 attacks. A local attacker could\nuse this to expose sensitive information. (CVE-2019-7308)\n\nIt was discovered that a use-after-free vulnerability existed in the user-\nspace API for crypto (af_alg) implementation in the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2019-8912)\n\nJakub Jirasek discovered a use-after-free vulnerability in the SCTP\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2019-8956)\n\nIt was discovered that the Linux kernel did not properly deallocate memory\nwhen handling certain errors while reading files. A local attacker could\nuse this to cause a denial of service (excessive memory consumption).\n(CVE-2019-8980)\n\nIt was discovered that a use-after-free vulnerability existed in the IPMI\nimplementation in the Linux kernel. A local attacker with access to the\nIPMI character device files could use this to cause a denial of service\n(system crash). (CVE-2019-9003)\n\nJann Horn discovered that the SNMP NAT implementation in the Linux kernel\nperformed insufficient ASN.1 length checks. An attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2019-9162)\n\nJann Horn discovered that the mmap implementation in the Linux kernel did\nnot properly check for the mmap minimum address in some situations. A local\nattacker could use this to assist exploiting a kernel NULL pointer\ndereference vulnerability. (CVE-2019-9213)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux-azure","version":"4.18.0-1014.14~18.04.1","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-hwe","version":"4.18.0-17.18~18.04.1","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.18.0-1014-azure","version":"4.18.0-1014.14~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure/4.18.0-1014.14~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-17-generic","version":"4.18.0-17.18~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.18.0-17.18~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-17-generic-lpae","version":"4.18.0-17.18~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.18.0-17.18~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-17-lowlatency","version":"4.18.0-17.18~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.18.0-17.18~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-17-snapdragon","version":"4.18.0-17.18~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.18.0-17.18~18.04.1","pocket":"security"},{"name":"linux-image-azure","version":"4.18.0.1014.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure/4.18.0.1014.13","pocket":"security"},{"name":"linux-image-generic-hwe-18.04","version":"4.18.0.17.67","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.17.67","pocket":"security"},{"name":"linux-image-generic-lpae-hwe-18.04","version":"4.18.0.17.67","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.17.67","pocket":"security"},{"name":"linux-image-lowlatency-hwe-18.04","version":"4.18.0.17.67","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.17.67","pocket":"security"},{"name":"linux-image-snapdragon-hwe-18.04","version":"4.18.0.17.67","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.17.67","pocket":"security"},{"name":"linux-image-virtual-hwe-18.04","version":"4.18.0.17.67","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.17.67","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19824","CVE-2019-3459","CVE-2019-3460","CVE-2019-6974","CVE-2019-7221","CVE-2019-7222","CVE-2019-7308","CVE-2019-8912","CVE-2019-8956","CVE-2019-8980","CVE-2019-9003","CVE-2019-9162","CVE-2019-9213"]},{"id":"USN-3930-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-04-02T18:21:40.890262","description":"Mathias Payer and Hui Peng discovered a use-after-free vulnerability in the\nAdvanced Linux Sound Architecture (ALSA) subsystem. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-19824)\n\nShlomi Oberman, Yuli Shapiro, and Ran Menscher discovered an information\nleak in the Bluetooth implementation of the Linux kernel. An attacker\nwithin Bluetooth range could use this to expose sensitive information\n(kernel memory). (CVE-2019-3459, CVE-2019-3460)\n\nJann Horn discovered that the KVM implementation in the Linux kernel\ncontained a use-after-free vulnerability. An attacker in a guest VM with\naccess to /dev/kvm could use this to cause a denial of service (guest VM\ncrash). (CVE-2019-6974)\n\nJim Mattson and Felix Wilhelm discovered a use-after-free vulnerability in\nthe KVM subsystem of the Linux kernel, when using nested virtual machines.\nA local attacker in a guest VM could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code in the host system.\n(CVE-2019-7221)\n\nFelix Wilhelm discovered that an information leak vulnerability existed in\nthe KVM subsystem of the Linux kernel, when nested virtualization is used.\nA local attacker could use this to expose sensitive information (host\nsystem memory to a guest VM). (CVE-2019-7222)\n\nJann Horn discovered that the eBPF implementation in the Linux kernel was\ninsufficiently hardened against Spectre V1 attacks. A local attacker could\nuse this to expose sensitive information. (CVE-2019-7308)\n\nIt was discovered that a use-after-free vulnerability existed in the user-\nspace API for crypto (af_alg) implementation in the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2019-8912)\n\nJakub Jirasek discovered a use-after-free vulnerability in the SCTP\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2019-8956)\n\nIt was discovered that the Linux kernel did not properly deallocate memory\nwhen handling certain errors while reading files. A local attacker could\nuse this to cause a denial of service (excessive memory consumption).\n(CVE-2019-8980)\n\nIt was discovered that a use-after-free vulnerability existed in the IPMI\nimplementation in the Linux kernel. A local attacker with access to the\nIPMI character device files could use this to cause a denial of service\n(system crash). (CVE-2019-9003)\n\nJann Horn discovered that the SNMP NAT implementation in the Linux kernel\nperformed insufficient ASN.1 length checks. An attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2019-9162)\n\nJann Horn discovered that the mmap implementation in the Linux kernel did\nnot properly check for the mmap minimum address in some situations. A local\nattacker could use this to assist exploiting a kernel NULL pointer\ndereference vulnerability. (CVE-2019-9213)\n","is_hidden":false,"release_packages":{"cosmic":[{"name":"linux","version":"4.18.0-17.18","description":"Linux kernel","is_source":true},{"name":"linux-kvm","version":"4.18.0-1009.9","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-aws","version":"4.18.0-1012.14","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-raspi2","version":"4.18.0-1011.13","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-azure","version":"4.18.0-1014.14","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-gcp","version":"4.18.0-1008.9","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-image-gke","version":"4.18.0.1008.8","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-17-snapdragon","version":"4.18.0-17.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-17.18"},{"name":"linux-image-generic","version":"4.18.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-17-generic-lpae","version":"4.18.0-17.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-17.18"},{"name":"linux-image-gcp","version":"4.18.0.1008.8","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-azure","version":"4.18.0.1014.15","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-1012-aws","version":"4.18.0-1012.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.18.0-1012.14"},{"name":"linux-image-virtual","version":"4.18.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-1011-raspi2","version":"4.18.0-1011.13","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.18.0-1011.13"},{"name":"linux-image-raspi2","version":"4.18.0.1011.8","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-1014-azure","version":"4.18.0-1014.14","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.18.0-1014.14"},{"name":"linux-image-generic-lpae","version":"4.18.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-snapdragon","version":"4.18.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-17-generic","version":"4.18.0-17.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-17.18"},{"name":"linux-image-kvm","version":"4.18.0.1009.9","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-1009-kvm","version":"4.18.0-1009.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.18.0-1009.9"},{"name":"linux-image-4.18.0-1008-gcp","version":"4.18.0-1008.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-gcp/4.18.0-1008.9"},{"name":"linux-image-lowlatency","version":"4.18.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-17-lowlatency","version":"4.18.0-17.18","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-17.18"},{"name":"linux-image-aws","version":"4.18.0.1012.12","is_source":false,"source_link":null,"version_link":null}]},"type":"USN","cves_ids":["CVE-2018-19824","CVE-2019-3459","CVE-2019-3460","CVE-2019-6974","CVE-2019-7221","CVE-2019-7222","CVE-2019-7308","CVE-2019-8912","CVE-2019-8956","CVE-2019-8980","CVE-2019-9003","CVE-2019-9162","CVE-2019-9213"]}]},{"id":"CVE-2019-9081","published":"2019-02-24T17:29:00","updated_at":"2025-08-04T19:34:49.269785+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none.\nReason: This candidate was withdrawn by its CNA. Further investigation\nshowed that it was not a security issue. Notes: none","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2019-9081"],"bugs":[""],"patches":{"php-laravel-framework":[]},"tags":{},"packages":[{"name":"php-laravel-framework","source":"https://ubuntu.com/security/cve?package=php-laravel-framework","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php-laravel-framework","debian":"https://tracker.debian.org/pkg/php-laravel-framework","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":50180,"limit":20,"total_results":79316}