{"cves":[{"id":"CVE-2019-5736","published":"2019-02-11T19:29:00","updated_at":"2025-08-25T23:12:30.746887+00:00","description":"\nrunc through 1.0-rc6, as used in Docker before 18.09.2 and other products,\nallows attackers to overwrite the host runc binary (and consequently obtain\nhost root access) by leveraging the ability to execute a command as root\nwithin one of these types of containers: (1) a new container with an\nattacker-controlled image, or (2) an existing container, to which the\nattacker previously had write access, that can be attached with docker\nexec. This occurs because of file-descriptor mishandling, related to\n/proc/self/exe.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2019/02/11/2","https://www.cve.org/CVERecord?id=CVE-2019-5736","https://ubuntu.com/security/notices/USN-4048-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922050"],"patches":{"runc":[],"docker.io":[]},"tags":{},"packages":[{"name":"docker.io","source":"https://ubuntu.com/security/cve?package=docker.io","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=docker.io","debian":"https://tracker.debian.org/pkg/docker.io","statuses":[{"release_codename":"bionic","status":"released","description":"18.06.1-0ubuntu1.2~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"18.06.1-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"18.09.5-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"18.06.1-0ubuntu1.2~16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]},{"name":"runc","source":"https://ubuntu.com/security/cve?package=runc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=runc","debian":"https://tracker.debian.org/pkg/runc","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.0~rc4+dfsg1-6ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.0~rc4+dfsg1-6ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.0.0~rc7+git20190403.029124da-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.0~rc2+docker1.13.1-0ubuntu1~16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4048-1"],"notices":[{"id":"USN-4048-1","title":"Docker vulnerabilities","summary":"Docker could be made to overwrite files as the administrator.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2019-07-08T14:41:56.088818","description":"Aleksa Sarai discovered that Docker was vulnerable to a directory traversal\nattack. An attacker could use this vulnerability to read and write arbitrary\nfiles on the host filesystem as root.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"docker.io","version":"18.09.7-0ubuntu1~18.04.3","description":"Linux container runtime","is_source":true},{"name":"docker-doc","version":"18.09.7-0ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.04.3","pocket":"security"},{"name":"docker.io","version":"18.09.7-0ubuntu1~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.04.3","pocket":"security"},{"name":"golang-docker-dev","version":"18.09.7-0ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.04.3","pocket":"security"},{"name":"golang-github-docker-docker-dev","version":"18.09.7-0ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.04.3","pocket":"security"},{"name":"vim-syntax-docker","version":"18.09.7-0ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.04.3","pocket":"security"}],"cosmic":[{"name":"docker.io","version":"18.09.7-0ubuntu1~18.10.3","description":"Linux container runtime","is_source":true},{"name":"docker-doc","version":"18.09.7-0ubuntu1~18.10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.10.3"},{"name":"docker.io","version":"18.09.7-0ubuntu1~18.10.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.10.3"},{"name":"golang-docker-dev","version":"18.09.7-0ubuntu1~18.10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.10.3"},{"name":"golang-github-docker-docker-dev","version":"18.09.7-0ubuntu1~18.10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.10.3"},{"name":"vim-syntax-docker","version":"18.09.7-0ubuntu1~18.10.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~18.10.3"}],"disco":[{"name":"docker.io","version":"18.09.7-0ubuntu1~19.04.4","description":"Linux container runtime","is_source":true},{"name":"docker-doc","version":"18.09.7-0ubuntu1~19.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~19.04.4"},{"name":"docker.io","version":"18.09.7-0ubuntu1~19.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~19.04.4"},{"name":"golang-docker-dev","version":"18.09.7-0ubuntu1~19.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~19.04.4"},{"name":"golang-github-docker-docker-dev","version":"18.09.7-0ubuntu1~19.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~19.04.4"},{"name":"vim-syntax-docker","version":"18.09.7-0ubuntu1~19.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~19.04.4"}],"xenial":[{"name":"docker.io","version":"18.09.7-0ubuntu1~16.04.4","description":"Linux container runtime","is_source":true},{"name":"docker-doc","version":"18.09.7-0ubuntu1~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~16.04.4","pocket":"security"},{"name":"docker.io","version":"18.09.7-0ubuntu1~16.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~16.04.4","pocket":"security"},{"name":"golang-docker-dev","version":"18.09.7-0ubuntu1~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~16.04.4","pocket":"security"},{"name":"golang-github-docker-docker-dev","version":"18.09.7-0ubuntu1~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~16.04.4","pocket":"security"},{"name":"vim-syntax-docker","version":"18.09.7-0ubuntu1~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/docker.io","version_link":"https://launchpad.net/ubuntu/+source/docker.io/18.09.7-0ubuntu1~16.04.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-15664","CVE-2019-5736"]}]},{"id":"CVE-2019-7733","published":"2019-02-11T17:29:00","updated_at":"2025-08-26T12:17:29.659611+00:00","description":"\nIn Live555 0.95, there is a buffer overflow via a large integer in a\nContent-Length HTTP header because handleRequestBytes has an unrestricted\nmemmove.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/rgaufman/live555/issues/21","https://www.cve.org/CVERecord?id=CVE-2019-7733"],"bugs":[""],"patches":{"liblivemedia":[]},"tags":{},"packages":[{"name":"liblivemedia","source":"https://ubuntu.com/security/cve?package=liblivemedia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=liblivemedia","debian":"https://tracker.debian.org/pkg/liblivemedia","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7732","published":"2019-02-11T17:29:00","updated_at":"2025-08-25T23:14:40.204577+00:00","description":"\nIn Live555 0.95, a setup packet can cause a memory leak leading to DoS\nbecause, when there are multiple instances of a single field (username,\nrealm, nonce, uri, or response), only the last instance can ever be freed.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"According to upstream:\nActually, this is not a memory leak. The parameters to\n“parseAuthorizationHeader()” are reference parameters (to pointers).\nThe allocated memory is passed back to the calling function, which\nends up deleting them all. So, there’s no bug here."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/rgaufman/live555/issues/20","https://www.cve.org/CVERecord?id=CVE-2019-7732"],"bugs":[""],"patches":{"liblivemedia":[]},"tags":{},"packages":[{"name":"liblivemedia","source":"https://ubuntu.com/security/cve?package=liblivemedia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=liblivemedia","debian":"https://tracker.debian.org/pkg/liblivemedia","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-15586","published":"2019-02-11T17:29:00","updated_at":"2025-08-25T22:48:13.288835+00:00","description":"\nEnigmail before 2.0.6 is prone to to OpenPGP signatures being spoofed for\narbitrary messages using a PGP/INLINE signature wrapped within a specially\ncrafted multipart HTML email.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/enigmail/bugs/849/","https://www.cve.org/CVERecord?id=CVE-2018-15586"],"bugs":[""],"patches":{"enigmail":[]},"tags":{},"packages":[{"name":"enigmail","source":"https://ubuntu.com/security/cve?package=enigmail","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=enigmail","debian":"https://tracker.debian.org/pkg/enigmail","statuses":[{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2:2.0.8-0ubuntu1~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:2.0.6.1-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2:2.0.8-1~ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [2:2.0.8-1~ubuntu0.14.04.2]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-20587","published":"2019-02-11T12:29:00","updated_at":"2025-07-17T16:43:07.428388+00:00","description":"\nBitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x\nbefore 0.17.1.knots20181229 have Incorrect Access Control. Local users can\nexploit this to steal currency by binding the RPC IPv4 localhost port, and\nforwarding requests to the IPv6 localhost port.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-20587","https://medium.com/@lukedashjr/cve-2018-20587-advisory-and-full-disclosure-a3105551e78b","https://www.cve.org/CVERecord?id=CVE-2018-20587"],"bugs":[""],"patches":{"bitcoin":[]},"tags":{},"packages":[{"name":"bitcoin","source":"https://ubuntu.com/security/cve?package=bitcoin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bitcoin","debian":"https://tracker.debian.org/pkg/bitcoin","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-6975","published":"2019-02-11T00:00:00","updated_at":"2025-08-25T23:14:09.887335+00:00","description":"\nDjango 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6\nallows Uncontrolled Memory Consumption via a malicious attacker-supplied\nvalue to the django.utils.numberformat.format() function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.djangoproject.com/weblog/2019/feb/11/security-releases/","https://docs.djangoproject.com/en/dev/releases/security/","https://groups.google.com/forum/#!topic/django-announce/WTwEAprR0IQ","https://www.openwall.com/lists/oss-security/2019/02/11/1","https://ubuntu.com/security/notices/USN-3890-1","https://www.cve.org/CVERecord?id=CVE-2019-6975"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922027"],"patches":{"python-django":["upstream: https://github.com/django/django/commit/0bbb560183fabf0533289700845dafa94951f227"]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"bionic","status":"released","description":"1:1.11.11-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:1.11.15-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.11.19","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.7-1ubuntu5.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-3890-1"],"notices":[{"id":"USN-3890-1","title":"Django vulnerability","summary":"Django could be made to consume resources if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-02-13T14:10:02.986464","description":"It was discovered that Django incorrectly handled formatting certain\nnumbers. A remote attacker could possibly use this issue to cause Django to\nconsume resources, leading to a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"python-django","version":"1:1.11.11-1ubuntu1.3","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1:1.11.11-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.3","pocket":"security"},{"name":"python-django-common","version":"1:1.11.11-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.3","pocket":"security"},{"name":"python-django-doc","version":"1:1.11.11-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.3","pocket":"security"},{"name":"python3-django","version":"1:1.11.11-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.3","pocket":"security"}],"cosmic":[{"name":"python-django","version":"1:1.11.15-1ubuntu1.2","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1:1.11.15-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.15-1ubuntu1.2"},{"name":"python-django-common","version":"1:1.11.15-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.15-1ubuntu1.2"},{"name":"python-django-doc","version":"1:1.11.15-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.15-1ubuntu1.2"},{"name":"python3-django","version":"1:1.11.15-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1:1.11.15-1ubuntu1.2"}],"xenial":[{"name":"python-django","version":"1.8.7-1ubuntu5.8","description":"High-level Python web development framework","is_source":true},{"name":"python-django","version":"1.8.7-1ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.8","pocket":"security"},{"name":"python-django-common","version":"1.8.7-1ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.8","pocket":"security"},{"name":"python-django-doc","version":"1.8.7-1ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.8","pocket":"security"},{"name":"python3-django","version":"1.8.7-1ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-django","version_link":"https://launchpad.net/ubuntu/+source/python-django/1.8.7-1ubuntu5.8","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-6975"]}]},{"id":"CVE-2019-6215","published":"2019-02-11T00:00:00","updated_at":"2025-08-25T23:13:41.245673+00:00","description":"\nA type confusion issue was addressed with improved memory handling. This\nissue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for\nWindows, iCloud for Windows 7.10. Processing maliciously crafted web\ncontent may lead to arbitrary code execution.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2019-0001.html","https://ubuntu.com/security/notices/USN-3889-1","https://www.cve.org/CVERecord?id=CVE-2019-6215"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.22.6-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.22.6-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.6","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3889-1"],"notices":[{"id":"USN-3889-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2019-02-13T14:04:19.081411","description":"A large number of security issues were discovered in the WebKitGTK+ Web\nand JavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"webkit2gtk","version":"2.22.6-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"webkit2gtk","version":"2.22.6-0ubuntu0.18.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"gir1.2-webkit2-4.0","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"webkit2gtk-driver","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"}]},"type":"USN","cves_ids":["CVE-2019-6212","CVE-2019-6215"]}]},{"id":"CVE-2019-6212","published":"2019-02-11T00:00:00","updated_at":"2025-08-25T23:13:41.245673+00:00","description":"\nMultiple memory corruption issues were addressed with improved memory\nhandling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3,\niTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously\ncrafted web content may lead to arbitrary code execution.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2019-0001.html","https://ubuntu.com/security/notices/USN-3889-1","https://www.cve.org/CVERecord?id=CVE-2019-6212"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.22.6-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.22.6-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.6","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.22.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3889-1"],"notices":[{"id":"USN-3889-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2019-02-13T14:04:19.081411","description":"A large number of security issues were discovered in the WebKitGTK+ Web\nand JavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"webkit2gtk","version":"2.22.6-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.22.6-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"webkit2gtk","version":"2.22.6-0ubuntu0.18.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"gir1.2-webkit2-4.0","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"},{"name":"webkit2gtk-driver","version":"2.22.6-0ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.6-0ubuntu0.18.10.1"}]},"type":"USN","cves_ids":["CVE-2019-6212","CVE-2019-6215"]}]},{"id":"CVE-2019-3827","published":"2019-02-11T00:00:00","updated_at":"2025-08-25T23:11:50.307945+00:00","description":"\nAn incorrect permission check in the admin backend in gvfs before version\n1.39.4 was found that allows reading and modify arbitrary files by\nprivileged users without asking for password when no authentication agent\nis running. This vulnerability can be exploited by malicious programs\nrunning under privileges of users belonging to the wheel group to further\nescalate its privileges by modifying system files without user's knowledge.\nSuccessful exploitation requires uncommon system configuration.","ubuntu_description":"","notes":[{"author":"debian","note":"Affecting vgfs since 1.29.4 where admin backend was introduced."}],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gitlab.gnome.org/GNOME/gvfs/issues/355","https://bugzilla.redhat.com/show_bug.cgi?id=1665578","https://ubuntu.com/security/notices/USN-3888-1","https://www.cve.org/CVERecord?id=CVE-2019-3827"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921816"],"patches":{"gvfs":[]},"tags":{},"packages":[{"name":"gvfs","source":"https://ubuntu.com/security/cve?package=gvfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gvfs","debian":"https://tracker.debian.org/pkg/gvfs","statuses":[{"release_codename":"bionic","status":"released","description":"1.36.1-0ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.38.1-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.38.1-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3888-1"],"notices":[{"id":"USN-3888-1","title":"GVfs vulnerability","summary":"GVfs could be made to expose sensitive information if it received\na specially crafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-02-12T16:42:33.890546","description":"It was discovered that GVfs incorrectly handled certain inputs. An attacker\ncould possibly use this issue to access sensitive information.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"gvfs","version":"1.36.1-0ubuntu1.3","description":"userspace virtual filesystem - GIO module","is_source":true},{"name":"gvfs","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"},{"name":"gvfs-backends","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"},{"name":"gvfs-bin","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"},{"name":"gvfs-common","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"},{"name":"gvfs-daemons","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"},{"name":"gvfs-fuse","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"},{"name":"gvfs-libs","version":"1.36.1-0ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.36.1-0ubuntu1.3","pocket":"security"}],"cosmic":[{"name":"gvfs","version":"1.38.1-0ubuntu1.2","description":"userspace virtual filesystem - GIO module","is_source":true},{"name":"gvfs","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"},{"name":"gvfs-backends","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"},{"name":"gvfs-bin","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"},{"name":"gvfs-common","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"},{"name":"gvfs-daemons","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"},{"name":"gvfs-fuse","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"},{"name":"gvfs-libs","version":"1.38.1-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gvfs","version_link":"https://launchpad.net/ubuntu/+source/gvfs/1.38.1-0ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2019-3827"]}]},{"id":"CVE-2018-15587","published":"2019-02-11T00:00:00","updated_at":"2025-08-18T17:07:44.260998+00:00","description":"\nGNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed\nfor arbitrary messages using a specially crafted email that contains a\nvalid signature from the entity to be impersonated as an attachment.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"looks like there are two issues here:\n#1- evolution shows security bar at bottom of message\n#2- mail that is not encrypted looks encrypted"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3998-1","https://www.cve.org/CVERecord?id=CVE-2018-15587"],"bugs":["https://gitlab.gnome.org/GNOME/evolution/issues/120","https://bugzilla.gnome.org/show_bug.cgi?id=796424","https://gitlab.gnome.org/GNOME/evolution-data-server/issues/3","https://gitlab.gnome.org/GNOME/evolution-data-server/issues/75","https://dev.gnupg.org/T4000"],"patches":{"evolution":["upstream: https://gitlab.gnome.org/GNOME/evolution/commit/9c55a311325f5905d8b8403b96607e46cf343f21","upstream: https://gitlab.gnome.org/GNOME/evolution/commit/f66cd3e1db301d264563b4222a3574e2e58e2b85"],"evolution-data-server":["upstream: https://gitlab.gnome.org/GNOME/evolution-data-server/commit/93306a296c64b48d12c356804f131048643eaa0a","upstream: https://gitlab.gnome.org/GNOME/evolution-data-server/commit/accb0e2415681565e4dac00cf1c4303c313ad29e","upstream: https://gitlab.gnome.org/GNOME/evolution-data-server/commit/5cd59aee67450e8750eb3cb2d357d0947f199f61"]},"tags":{},"packages":[{"name":"evolution","source":"https://ubuntu.com/security/cve?package=evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution","debian":"https://tracker.debian.org/pkg/evolution","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.31.90-1","component":null,"pocket":"security"}]},{"name":"evolution-data-server","source":"https://ubuntu.com/security/cve?package=evolution-data-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution-data-server","debian":"https://tracker.debian.org/pkg/evolution-data-server","statuses":[{"release_codename":"groovy","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.28.5-0ubuntu0.18.04.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"3.30.5-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.18.5-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.31.90-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.31.90-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3998-1"],"notices":[{"id":"USN-3998-1","title":"Evolution Data Server vulnerability","summary":"Evolution Data Server would sometimes display email content as encrypted\nwhen it was not.\n","instructions":"After a standard system update you need to restart Evolution to make\nall the necessary changes.\n","references":[],"published":"2019-05-30T11:41:05.639416","description":"Marcus Brinkmann discovered that Evolution Data Server did not correctly\ninterpret the output from GPG when decrypting encrypted messages. Under\ncertain circumstances, this could result in displaying clear-text portions\nof encrypted messages as though they were encrypted.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"evolution-data-server","version":"3.28.5-0ubuntu0.18.04.2","description":"Evolution suite data server","is_source":true},{"name":"evolution-data-server","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"evolution-data-server-common","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"evolution-data-server-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"evolution-data-server-doc","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"evolution-data-server-online-accounts","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"evolution-data-server-tests","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"gir1.2-camel-1.2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"gir1.2-ebook-1.2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"gir1.2-ebookcontacts-1.2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"gir1.2-edataserver-1.2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"gir1.2-edataserverui-1.2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libcamel-1.2-61","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libcamel1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libebackend-1.2-10","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libebackend1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libebook-1.2-19","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libebook-contacts-1.2-2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libebook-contacts1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libebook1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libecal-1.2-19","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libecal1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedata-book-1.2-25","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedata-book1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedata-cal-1.2-28","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedata-cal1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedataserver-1.2-23","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedataserver1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedataserverui-1.2-2","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"},{"name":"libedataserverui1.2-dev","version":"3.28.5-0ubuntu0.18.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2","pocket":"security"}],"xenial":[{"name":"evolution-data-server","version":"3.18.5-1ubuntu1.2","description":"Evolution suite data server","is_source":true},{"name":"evolution-data-server","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"evolution-data-server-common","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"evolution-data-server-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"evolution-data-server-doc","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"evolution-data-server-online-accounts","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"gir1.2-ebook-1.2","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"gir1.2-ebookcontacts-1.2","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"gir1.2-edataserver-1.2","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libcamel-1.2-54","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libcamel1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libebackend-1.2-10","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libebackend1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libebook-1.2-16","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libebook-contacts-1.2-2","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libebook-contacts1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libebook1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libecal-1.2-19","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libecal1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedata-book-1.2-25","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedata-book1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedata-cal-1.2-28","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedata-cal1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedataserver-1.2-21","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedataserver1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedataserverui-1.2-1","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"},{"name":"libedataserverui1.2-dev","version":"3.18.5-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-15587"]}]},{"id":"CVE-2019-7704","published":"2019-02-10T22:29:00","updated_at":"2025-07-17T16:43:36.913494+00:00","description":"\nwasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen\n1.38.22 triggers an attempt at excessive memory allocation, as demonstrated\nby wasm-merge and wasm-opt.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/1866","https://www.cve.org/CVERecord?id=CVE-2019-7704"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"64-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7703","published":"2019-02-10T22:29:00","updated_at":"2025-07-17T16:43:36.913494+00:00","description":"\nIn Binaryen 1.38.22, there is a use-after-free problem in\nwasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote attackers\ncould leverage this vulnerability to cause a denial-of-service via a wasm\nfile, as demonstrated by wasm-merge.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/1865","https://www.cve.org/CVERecord?id=CVE-2019-7703"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"64-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7702","published":"2019-02-10T22:29:00","updated_at":"2025-07-17T16:43:36.913494+00:00","description":"\nA NULL pointer dereference was discovered in\nwasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in\nBinaryen 1.38.22. A crafted wasm input can cause a segmentation fault,\nleading to denial-of-service, as demonstrated by wasm-as.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/1867","https://www.cve.org/CVERecord?id=CVE-2019-7702"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"64-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7701","published":"2019-02-10T22:29:00","updated_at":"2025-07-17T16:43:36.913494+00:00","description":"\nA heap-based buffer over-read was discovered in\nwasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen\n1.38.22. A crafted wasm input can cause a segmentation fault, leading to\ndenial-of-service, as demonstrated by wasm2js.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/1863","https://www.cve.org/CVERecord?id=CVE-2019-7701"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"64-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7700","published":"2019-02-10T22:29:00","updated_at":"2025-07-11T07:42:52.647340+00:00","description":"\nA heap-based buffer over-read was discovered in\nwasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22.\nA crafted wasm input can cause a segmentation fault, leading to\ndenial-of-service, as demonstrated by wasm-merge.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/1864","https://www.cve.org/CVERecord?id=CVE-2019-7700"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7699","published":"2019-02-10T22:29:00","updated_at":"2025-07-11T07:42:52.647340+00:00","description":"\nA heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in\nCodecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remote attackers could\nleverage this vulnerability to cause an exception via crafted mp4 input,\nwhich leads to a denial of service.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/axiomatic-systems/Bento4/issues/355","https://www.cve.org/CVERecord?id=CVE-2019-7699"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7698","published":"2019-02-10T22:29:00","updated_at":"2025-07-11T07:42:49.742442+00:00","description":"\nAn issue was discovered in AP4_Array::EnsureCapacity in\nCore/Ap4Array.h in Bento4 1.5.1-627. Crafted MP4 input triggers an attempt\nat excessive memory allocation, as demonstrated by mp42hls, a related issue\nto CVE-2018-20095.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/axiomatic-systems/Bento4/issues/354","https://www.cve.org/CVERecord?id=CVE-2019-7698"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7697","published":"2019-02-10T22:29:00","updated_at":"2025-07-11T07:42:49.742442+00:00","description":"\nAn issue was discovered in Bento4 v1.5.1-627. There is an assertion failure\nin AP4_AtomListWriter::Action in Core/Ap4Atom.cpp, leading to a denial of\nservice (program crash), as demonstrated by mp42hls.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/axiomatic-systems/Bento4/issues/351","https://www.cve.org/CVERecord?id=CVE-2019-7697"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7664","published":"2019-02-09T16:29:00","updated_at":"2025-08-25T23:14:40.204577+00:00","description":"\nIn elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in\nlibelf/note_xlate.h because of an incorrect overflow check. Crafted elf\ninput causes a segmentation fault, leading to denial of service (program\ncrash).","ubuntu_description":"","notes":[{"author":"ccdm94","note":"the vulnerable code was introduced in version 0.173."}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2019-7664"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=921881","https://sourceware.org/bugzilla/show_bug.cgi?id=24084"],"patches":{"elfutils":["upstream: https://sourceware.org/git/?p=elfutils.git;a=commit;h=e65d91d21cb09d83b001fef9435e576ba447db32"]},"tags":{},"packages":[{"name":"elfutils","source":"https://ubuntu.com/security/cve?package=elfutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=elfutils","debian":"https://tracker.debian.org/pkg/elfutils","statuses":[{"release_codename":"jammy","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.170-0.4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.170-0.5.0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.176-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.176-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.176-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.165-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"0.158-0ubuntu5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-7662","published":"2019-02-09T16:29:00","updated_at":"2025-08-25T23:14:40.204577+00:00","description":"\nAn assertion failure was discovered in wasm::WasmBinaryBuilder::getType()\nin wasm-binary.cpp in Binaryen 1.38.22. This allows remote attackers to\ncause a denial of service (failed assertion and crash) via a crafted wasm\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/WebAssembly/binaryen/issues/1872","https://www.cve.org/CVERecord?id=CVE-2019-7662"],"bugs":[""],"patches":{"binaryen":[]},"tags":{},"packages":[{"name":"binaryen","source":"https://ubuntu.com/security/cve?package=binaryen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binaryen","debian":"https://tracker.debian.org/pkg/binaryen","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"66-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":50320,"limit":20,"total_results":79316}