{"cves":[{"id":"CVE-2018-20662","published":"2019-01-03T00:00:00","updated_at":"2025-08-25T22:53:02.610254+00:00","description":"\nIn Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a\ndenial-of-service (application crash caused by Object.h SIGABRT, because of\na wrong return value from PDFDoc::setup) by crafting a PDF file in which an\nxref data structure is mishandled during extractPDFSubtype processing.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4042-1","https://www.cve.org/CVERecord?id=CVE-2018-20662"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=918158","https://gitlab.freedesktop.org/poppler/poppler/issues/706"],"patches":{"poppler":["upstream: https://gitlab.freedesktop.org/poppler/poppler/commit/7b4e372deeb716eb3fe3a54b31ed41af759224f9"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"bionic","status":"released","description":"0.62.0-2ubuntu2.9","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.68.0-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.74.0-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.14","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was deferred [2019-03-28]","component":null,"pocket":"security"}]}],"notices_ids":["USN-4042-1"],"notices":[{"id":"USN-4042-1","title":"poppler vulnerabilities","summary":"Several security issues were fixed in poppler.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-06-27T13:29:23.845161","description":"It was discovered that poppler incorrectly handled certain files. If a user\nor automated system were tricked into opening a crafted PDF file, an\nattacker could cause a denial of service, or possibly execute arbitrary\ncode\n","is_hidden":false,"release_packages":{"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.9","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.9","pocket":"security"}],"cosmic":[{"name":"poppler","version":"0.68.0-0ubuntu1.7","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-cpp-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-cpp0v5","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-glib-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-glib-doc","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-glib8","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-private-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-qt5-1","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler-qt5-dev","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"libpoppler79","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"},{"name":"poppler-utils","version":"0.68.0-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.7"}],"disco":[{"name":"poppler","version":"0.74.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-cpp-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-cpp0v5","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-glib-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-glib-doc","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-glib8","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-private-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-qt5-1","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler-qt5-dev","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"libpoppler85","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"},{"name":"poppler-utils","version":"0.74.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.74.0-0ubuntu1.2"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.14","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.14","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-9865","CVE-2018-18897","CVE-2018-20662","CVE-2019-10018","CVE-2019-10019","CVE-2019-10021","CVE-2019-10023","CVE-2019-10872","CVE-2019-10873","CVE-2019-12293","CVE-2019-9200","CVE-2019-9631","CVE-2019-9903"]}]},{"id":"CVE-2018-16882","published":"2019-01-03T00:00:00","updated_at":"2026-07-04T07:46:10.841036+00:00","description":"\nA use-after-free issue was found in the way the Linux kernel's KVM\nhypervisor processed posted interrupts when nested(=1) virtualization is\nenabled. In nested_get_vmcs12_pages(), in case of an error while processing\nposted interrupt address, it unmaps the 'pi_desc_page' without resetting\n'pi_desc' descriptor address, which is later used in\npi_test_and_clear_on(). A guest user/process could use this flaw to crash\nthe host kernel resulting in DoS or potentially gain privileged access to a\nsystem. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.","ubuntu_description":"\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine.","notes":[{"author":"tyhicks","note":"Ubuntu kernels do not enable nested KVM virtualization by default and\nare unaffected by this flaw in the default configuration. To ensure that\nnested virtualization is not enabled, verify that the\n/sys/module/kvm_intel/parameters/nested file contains \"N\"."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2018/12/18/6","https://marc.info/?l=kvm&m=154514994222809&w=2","https://ubuntu.com/security/notices/USN-3871-1","https://ubuntu.com/security/notices/USN-3872-1","https://ubuntu.com/security/notices/USN-3871-3","https://ubuntu.com/security/notices/USN-3871-4","https://ubuntu.com/security/notices/USN-3878-1","https://ubuntu.com/security/notices/USN-3871-5","https://ubuntu.com/security/notices/USN-3878-2","https://www.cve.org/CVERecord?id=CVE-2018-16882"],"bugs":[""],"patches":{"linux":["break-fix: 5e2f30b756a37bd80c5b0471d0e10d769ab2eb9a c2dd5146e9fe1f22c77c1b011adf84eea0245806"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-gcp-edge":[],"linux-aws-hwe":[],"linux-oracle":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-44.47","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-14.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1032.34","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1008.10","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1032.34~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1037.39","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1008.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.15.0-1037.39~14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1037.39~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1037.39","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1037.39~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1027.28","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1006.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1027.28~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"bionic","status":"released","description":"4.18.0-1006.7~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"released","description":"4.18.0-14.15~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-45.48~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.0.0-8.9~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-45.48~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1029.29","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1007.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1004.9","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1033.38","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.15.0-1033.38","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1031.33","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.18.0-1009.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"}]}],"notices_ids":["USN-3878-1","USN-3871-4","USN-3871-1","USN-3871-5","USN-3872-1","USN-3878-2","USN-3871-3"],"notices":[{"id":"USN-3878-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-02-04T19:44:57.436788","description":"It was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the crypto subsystem of the Linux kernel leaked\nuninitialized memory to user space in some situations. A local attacker\ncould use this to expose sensitive information (kernel memory).\n(CVE-2018-19854)\n","is_hidden":false,"release_packages":{"cosmic":[{"name":"linux-raspi2","version":"4.18.0-1009.11","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-gcp","version":"4.18.0-1006.7","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux","version":"4.18.0-14.15","description":"Linux kernel","is_source":true},{"name":"linux-kvm","version":"4.18.0-1007.7","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-aws","version":"4.18.0-1008.10","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-image-kvm","version":"4.18.0.1007.7","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-gke","version":"4.18.0.1006.6","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-14-lowlatency","version":"4.18.0-14.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-14.15"},{"name":"linux-image-4.18.0-14-snapdragon","version":"4.18.0-14.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-14.15"},{"name":"linux-image-4.18.0-1007-kvm","version":"4.18.0-1007.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.18.0-1007.7"},{"name":"linux-image-generic","version":"4.18.0.14.15","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-gcp","version":"4.18.0.1006.6","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-14-generic","version":"4.18.0-14.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-14.15"},{"name":"linux-image-4.18.0-1008-aws","version":"4.18.0-1008.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.18.0-1008.10"},{"name":"linux-image-aws","version":"4.18.0.1008.8","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-generic-lpae","version":"4.18.0.14.15","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-snapdragon","version":"4.18.0.14.15","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.18.0-1009-raspi2","version":"4.18.0-1009.11","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.18.0-1009.11"},{"name":"linux-image-4.18.0-1006-gcp","version":"4.18.0-1006.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-gcp/4.18.0-1006.7"},{"name":"linux-image-4.18.0-14-generic-lpae","version":"4.18.0-14.15","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.18.0-14.15"},{"name":"linux-image-lowlatency","version":"4.18.0.14.15","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-raspi2","version":"4.18.0.1009.6","is_source":false,"source_link":null,"version_link":null}]},"type":"USN","cves_ids":["CVE-2018-14625","CVE-2018-16882","CVE-2018-19407","CVE-2018-19854"]},{"id":"USN-3871-4","title":"Linux kernel (HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-02-04T21:54:37.005356","description":"USN-3871-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu\n16.04 LTS.\n\nWen Xu discovered that a use-after-free vulnerability existed in the ext4\nfilesystem implementation in the Linux kernel. An attacker could use this\nto construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10876, CVE-2018-10879)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that an out-of-bounds write vulnerability existed in the\next4 filesystem implementation in the Linux kernel. An attacker could use\nthis to construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10878, CVE-2018-10882)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly ensure that xattr information remained in inode\nbodies. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10880)\n\nWen Xu discovered that the ext4 file system implementation in the Linux\nkernel could possibly perform an out of bounds write when updating the\njournal for an inline file. An attacker could use this to construct a\nmalicious ext4 image that, when mounted, could cause a denial of service\n(system crash). (CVE-2018-10883)\n\nIt was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nJann Horn discovered that the procfs file system implementation in the\nLinux kernel did not properly restrict the ability to inspect the kernel\nstack of an arbitrary task. A local attacker could use this to expose\nsensitive information. (CVE-2018-17972)\n\nJann Horn discovered that the mremap() system call in the Linux kernel did\nnot properly flush the TLB when completing, potentially leaving access to a\nphysical page after it has been released to the page allocator. A local\nattacker could use this to cause a denial of service (system crash), expose\nsensitive information, or possibly execute arbitrary code. (CVE-2018-18281)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the debug interface for the Linux kernel's HID\nsubsystem did not properly perform bounds checking in some situations. An\nattacker with access to debugfs could use this to cause a denial of service\nor possibly gain additional privileges. (CVE-2018-9516)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux-aws-hwe","version":"4.15.0-1032.34~16.04.1","description":"Linux kernel for Amazon Web Services (AWS-HWE) systems","is_source":true},{"name":"linux-gcp","version":"4.15.0-1027.28~16.04.1","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-hwe","version":"4.15.0-45.48~16.04.1","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.15.0-1027-gcp","version":"4.15.0-1027.28~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-gcp/4.15.0-1027.28~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-1032-aws","version":"4.15.0-1032.34~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-aws-hwe/4.15.0-1032.34~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-45-generic","version":"4.15.0-45.48~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.15.0-45.48~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-45-generic-lpae","version":"4.15.0-45.48~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-45.48~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-45-lowlatency","version":"4.15.0-45.48~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.15.0-45.48~16.04.1","pocket":"security"},{"name":"linux-image-aws-hwe","version":"4.15.0.1032.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-aws-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-aws-hwe/4.15.0.1032.33","pocket":"security"},{"name":"linux-image-gcp","version":"4.15.0.1027.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1027.41","pocket":"security"},{"name":"linux-image-generic-hwe-16.04","version":"4.15.0.45.66","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.45.66","pocket":"security"},{"name":"linux-image-generic-lpae-hwe-16.04","version":"4.15.0.45.66","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.45.66","pocket":"security"},{"name":"linux-image-gke","version":"4.15.0.1027.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1027.41","pocket":"security"},{"name":"linux-image-lowlatency-hwe-16.04","version":"4.15.0.45.66","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.45.66","pocket":"security"},{"name":"linux-image-oem","version":"4.15.0.45.66","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.45.66","pocket":"security"},{"name":"linux-image-virtual-hwe-16.04","version":"4.15.0.45.66","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.15.0.45.66","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10876","CVE-2018-10877","CVE-2018-10878","CVE-2018-10879","CVE-2018-10880","CVE-2018-10882","CVE-2018-10883","CVE-2018-14625","CVE-2018-16882","CVE-2018-17972","CVE-2018-18281","CVE-2018-19407","CVE-2018-9516"]},{"id":"USN-3871-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-01-29T02:49:23.373281","description":"Wen Xu discovered that a use-after-free vulnerability existed in the ext4\nfilesystem implementation in the Linux kernel. An attacker could use this\nto construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10876, CVE-2018-10879)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that an out-of-bounds write vulnerability existed in the\next4 filesystem implementation in the Linux kernel. An attacker could use\nthis to construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10878, CVE-2018-10882)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly ensure that xattr information remained in inode\nbodies. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10880)\n\nWen Xu discovered that the ext4 file system implementation in the Linux\nkernel could possibly perform an out of bounds write when updating the\njournal for an inline file. An attacker could use this to construct a\nmalicious ext4 image that, when mounted, could cause a denial of service\n(system crash). (CVE-2018-10883)\n\nIt was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nJann Horn discovered that the procfs file system implementation in the\nLinux kernel did not properly restrict the ability to inspect the kernel\nstack of an arbitrary task. A local attacker could use this to expose\nsensitive information. (CVE-2018-17972)\n\nJann Horn discovered that the mremap() system call in the Linux kernel did\nnot properly flush the TLB when completing, potentially leaving access to a\nphysical page after it has been released to the page allocator. A local\nattacker could use this to cause a denial of service (system crash), expose\nsensitive information, or possibly execute arbitrary code. (CVE-2018-18281)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the debug interface for the Linux kernel's HID\nsubsystem did not properly perform bounds checking in some situations. An\nattacker with access to debugfs could use this to cause a denial of service\nor possibly gain additional privileges. (CVE-2018-9516)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux","version":"4.15.0-44.47","description":"Linux kernel","is_source":true},{"name":"linux-image-4.15.0-44-generic","version":"4.15.0-44.47","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed","version_link":"https://launchpad.net/ubuntu/+source/linux-signed/4.15.0-44.47","pocket":"security"},{"name":"linux-image-4.15.0-44-generic-lpae","version":"4.15.0-44.47","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-44.47","pocket":"security"},{"name":"linux-image-4.15.0-44-lowlatency","version":"4.15.0-44.47","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed","version_link":"https://launchpad.net/ubuntu/+source/linux-signed/4.15.0-44.47","pocket":"security"},{"name":"linux-image-4.15.0-44-snapdragon","version":"4.15.0-44.47","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-44.47","pocket":"security"},{"name":"linux-image-generic","version":"4.15.0.44.46","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-generic-hwe-16.04","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-generic-hwe-16.04-edge","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-generic-lpae","version":"4.15.0.44.46","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-generic-lpae-hwe-16.04","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-generic-lpae-hwe-16.04-edge","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-lowlatency","version":"4.15.0.44.46","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-lowlatency-hwe-16.04","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-lowlatency-hwe-16.04-edge","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-snapdragon","version":"4.15.0.44.46","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-virtual","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-virtual-hwe-16.04","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"},{"name":"linux-image-virtual-hwe-16.04-edge","version":"4.15.0.44.46","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta","version_link":"https://launchpad.net/ubuntu/+source/linux-meta/4.15.0.44.46","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10876","CVE-2018-10877","CVE-2018-10878","CVE-2018-10879","CVE-2018-10880","CVE-2018-10882","CVE-2018-10883","CVE-2018-14625","CVE-2018-16882","CVE-2018-17972","CVE-2018-18281","CVE-2018-19407","CVE-2018-9516"]},{"id":"USN-3871-5","title":"Linux kernel (Azure) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-02-07T21:56:26.303779","description":"Wen Xu discovered that a use-after-free vulnerability existed in the ext4\nfilesystem implementation in the Linux kernel. An attacker could use this\nto construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10876, CVE-2018-10879)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that an out-of-bounds write vulnerability existed in the\next4 filesystem implementation in the Linux kernel. An attacker could use\nthis to construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10878, CVE-2018-10882)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly ensure that xattr information remained in inode\nbodies. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10880)\n\nWen Xu discovered that the ext4 file system implementation in the Linux\nkernel could possibly perform an out of bounds write when updating the\njournal for an inline file. An attacker could use this to construct a\nmalicious ext4 image that, when mounted, could cause a denial of service\n(system crash). (CVE-2018-10883)\n\nIt was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nJann Horn discovered that the procfs file system implementation in the\nLinux kernel did not properly restrict the ability to inspect the kernel\nstack of an arbitrary task. A local attacker could use this to expose\nsensitive information. (CVE-2018-17972)\n\nJann Horn discovered that the mremap() system call in the Linux kernel did\nnot properly flush the TLB when completing, potentially leaving access to a\nphysical page after it has been released to the page allocator. A local\nattacker could use this to cause a denial of service (system crash), expose\nsensitive information, or possibly execute arbitrary code. (CVE-2018-18281)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the debug interface for the Linux kernel's HID\nsubsystem did not properly perform bounds checking in some situations. An\nattacker with access to debugfs could use this to cause a denial of service\nor possibly gain additional privileges. (CVE-2018-9516)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux-azure","version":"4.15.0-1037.39","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-image-4.15.0-1037-azure","version":"4.15.0-1037.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure/4.15.0-1037.39","pocket":"security"},{"name":"linux-image-azure","version":"4.15.0.1037.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure/4.15.0.1037.37","pocket":"security"}],"trusty":[{"name":"linux-azure","version":"4.15.0-1037.39~14.04.2","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-image-4.15.0-1037-azure","version":"4.15.0-1037.39~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure/4.15.0-1037.39~14.04.2","pocket":"security"},{"name":"linux-image-azure","version":"4.15.0.1037.24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure/4.15.0.1037.24","pocket":"security"}],"xenial":[{"name":"linux-azure","version":"4.15.0-1037.39~16.04.1","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-image-4.15.0-1037-azure","version":"4.15.0-1037.39~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-azure/4.15.0-1037.39~16.04.1","pocket":"security"},{"name":"linux-image-azure","version":"4.15.0.1037.42","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-azure/4.15.0.1037.42","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10876","CVE-2018-10877","CVE-2018-10878","CVE-2018-10879","CVE-2018-10880","CVE-2018-10882","CVE-2018-10883","CVE-2018-14625","CVE-2018-16882","CVE-2018-17972","CVE-2018-18281","CVE-2018-19407","CVE-2018-9516"]},{"id":"USN-3872-1","title":"Linux kernel (HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-01-29T02:54:09.290168","description":"It was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the crypto subsystem of the Linux kernel leaked\nuninitialized memory to user space in some situations. A local attacker\ncould use this to expose sensitive information (kernel memory).\n(CVE-2018-19854)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux-hwe","version":"4.18.0-14.15~18.04.1","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.18.0-14-generic","version":"4.18.0-14.15~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.18.0-14.15~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-14-generic-lpae","version":"4.18.0-14.15~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.18.0-14.15~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-14-lowlatency","version":"4.18.0-14.15~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-hwe/4.18.0-14.15~18.04.1","pocket":"security"},{"name":"linux-image-4.18.0-14-snapdragon","version":"4.18.0-14.15~18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.18.0-14.15~18.04.1","pocket":"security"},{"name":"linux-image-generic-hwe-18.04","version":"4.18.0.14.64","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.14.64","pocket":"security"},{"name":"linux-image-generic-lpae-hwe-18.04","version":"4.18.0.14.64","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.14.64","pocket":"security"},{"name":"linux-image-lowlatency-hwe-18.04","version":"4.18.0.14.64","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.14.64","pocket":"security"},{"name":"linux-image-snapdragon-hwe-18.04","version":"4.18.0.14.64","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.14.64","pocket":"security"},{"name":"linux-image-virtual-hwe-18.04","version":"4.18.0.14.64","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-hwe/4.18.0.14.64","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-14625","CVE-2018-16882","CVE-2018-19407","CVE-2018-19854"]},{"id":"USN-3878-2","title":"Linux kernel (Azure) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-02-07T22:04:43.659638","description":"It was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the crypto subsystem of the Linux kernel leaked\nuninitialized memory to user space in some situations. A local attacker\ncould use this to expose sensitive information (kernel memory).\n(CVE-2018-19854)\n","is_hidden":false,"release_packages":{"cosmic":[{"name":"linux-azure","version":"4.18.0-1008.8","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-image-4.18.0-1008-azure","version":"4.18.0-1008.8","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.18.0-1008.8"},{"name":"linux-image-azure","version":"4.18.0.1008.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.18.0-1008.8"}]},"type":"USN","cves_ids":["CVE-2018-14625","CVE-2018-16882","CVE-2018-19407","CVE-2018-19854"]},{"id":"USN-3871-3","title":"Linux kernel (AWS, GCP, KVM, OEM, Raspberry Pi 2) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2019-02-04T23:00:32.430723","description":"Wen Xu discovered that a use-after-free vulnerability existed in the ext4\nfilesystem implementation in the Linux kernel. An attacker could use this\nto construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10876, CVE-2018-10879)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that an out-of-bounds write vulnerability existed in the\next4 filesystem implementation in the Linux kernel. An attacker could use\nthis to construct a malicious ext4 image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10878, CVE-2018-10882)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly ensure that xattr information remained in inode\nbodies. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10880)\n\nWen Xu discovered that the ext4 file system implementation in the Linux\nkernel could possibly perform an out of bounds write when updating the\njournal for an inline file. An attacker could use this to construct a\nmalicious ext4 image that, when mounted, could cause a denial of service\n(system crash). (CVE-2018-10883)\n\nIt was discovered that a race condition existed in the vsock address family\nimplementation of the Linux kernel that could lead to a use-after-free\ncondition. A local attacker in a guest virtual machine could use this to\nexpose sensitive information (host machine kernel memory). (CVE-2018-14625)\n\nCfir Cohen discovered that a use-after-free vulnerability existed in the\nKVM implementation of the Linux kernel, when handling interrupts in\nenvironments where nested virtualization is in use (nested KVM\nvirtualization is not enabled by default in Ubuntu kernels). A local\nattacker in a guest VM could possibly use this to gain administrative\nprivileges in a host machine. (CVE-2018-16882)\n\nJann Horn discovered that the procfs file system implementation in the\nLinux kernel did not properly restrict the ability to inspect the kernel\nstack of an arbitrary task. A local attacker could use this to expose\nsensitive information. (CVE-2018-17972)\n\nJann Horn discovered that the mremap() system call in the Linux kernel did\nnot properly flush the TLB when completing, potentially leaving access to a\nphysical page after it has been released to the page allocator. A local\nattacker could use this to cause a denial of service (system crash), expose\nsensitive information, or possibly execute arbitrary code. (CVE-2018-18281)\n\nWei Wu discovered that the KVM implementation in the Linux kernel did not\nproperly ensure that ioapics were initialized. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2018-19407)\n\nIt was discovered that the debug interface for the Linux kernel's HID\nsubsystem did not properly perform bounds checking in some situations. An\nattacker with access to debugfs could use this to cause a denial of service\nor possibly gain additional privileges. (CVE-2018-9516)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux-aws","version":"4.15.0-1032.34","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-gcp","version":"4.15.0-1027.28","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-kvm","version":"4.15.0-1029.29","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-oem","version":"4.15.0-1033.38","description":"Linux kernel for OEM processors","is_source":true},{"name":"linux-raspi2","version":"4.15.0-1031.33","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-image-4.15.0-1027-gcp","version":"4.15.0-1027.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-gcp/4.15.0-1027.28","pocket":"security"},{"name":"linux-image-4.15.0-1029-kvm","version":"4.15.0-1029.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.15.0-1029.29","pocket":"security"},{"name":"linux-image-4.15.0-1031-raspi2","version":"4.15.0-1031.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1031.33","pocket":"security"},{"name":"linux-image-4.15.0-1032-aws","version":"4.15.0-1032.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1032.34","pocket":"security"},{"name":"linux-image-4.15.0-1033-oem","version":"4.15.0-1033.38","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-signed-oem","version_link":"https://launchpad.net/ubuntu/+source/linux-signed-oem/4.15.0-1033.38","pocket":"security"},{"name":"linux-image-aws","version":"4.15.0.1032.31","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-aws/4.15.0.1032.31","pocket":"security"},{"name":"linux-image-gcp","version":"4.15.0.1027.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1027.29","pocket":"security"},{"name":"linux-image-gke","version":"4.15.0.1027.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-gcp/4.15.0.1027.29","pocket":"security"},{"name":"linux-image-kvm","version":"4.15.0.1029.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-kvm/4.15.0.1029.29","pocket":"security"},{"name":"linux-image-oem","version":"4.15.0.1033.38","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-oem","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-oem/4.15.0.1033.38","pocket":"security"},{"name":"linux-image-raspi2","version":"4.15.0.1031.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-meta-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-meta-raspi2/4.15.0.1031.29","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10876","CVE-2018-10877","CVE-2018-10878","CVE-2018-10879","CVE-2018-10880","CVE-2018-10882","CVE-2018-10883","CVE-2018-14625","CVE-2018-16882","CVE-2018-17972","CVE-2018-18281","CVE-2018-19407","CVE-2018-9516"]}]},{"id":"CVE-2018-19478","published":"2019-01-02T18:29:00","updated_at":"2025-08-25T22:51:44.236397+00:00","description":"\nIn Artifex Ghostscript before 9.26, a carefully crafted PDF file can\ntrigger an extremely long running computation when parsing the file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19478"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=699856"],"patches":{"ghostscript":["upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commitdiff;h=0a7e5a1c309fa0911b892fa40996a7d55d90bace"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"9.26~dfsg+0-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.26~dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19362","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have\nunspecified impact by leveraging failure to block the jboss-common-core\nclass from polymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-19362"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"hirsute","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.8","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2.9.8-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-19361","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have\nunspecified impact by leveraging failure to block the openjpa class from\npolymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-19361"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"hirsute","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.8","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.9.8-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-19360","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have\nunspecified impact by leveraging failure to block the axis2-transport-jms\nclass from polymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-19360"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"hirsute","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.8","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.9.8-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-14721","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:04:54.514762+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to\nconduct server-side request forgery (SSRF) attacks by leveraging failure to\nblock the axis2-jaxws class from polymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF).","notes":[],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-14721"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-14720","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:04:54.514762+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.7 might allow attackers to\nconduct external XML entity (XXE) attacks by leveraging failure to block\nunspecified JDK classes from polymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nXML entity (XXE) attacks.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-14720"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.9.8-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-14719","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:04:54.514762+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to\nexecute arbitrary code by leveraging failure to block the blaze-ds-opt and\nblaze-ds-core classes from polymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-14719"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"bionic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-14718","published":"2019-01-02T18:29:00","updated_at":"2025-08-26T12:04:54.514762+00:00","description":"\nFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to\nexecute arbitrary code by leveraging failure to block the slf4j-ext class\nfrom polymorphic deserialization.","ubuntu_description":"\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://ubuntu.com/security/notices/USN-4813-1","https://www.cve.org/CVERecord?id=CVE-2018-14718"],"bugs":[""],"patches":{"jackson-databind":[]},"tags":{},"packages":[{"name":"jackson-databind","source":"https://ubuntu.com/security/cve?package=jackson-databind","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jackson-databind","debian":"https://tracker.debian.org/pkg/jackson-databind","statuses":[{"release_codename":"bionic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.2-3ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.9.7","component":null,"pocket":"security"}]}],"notices_ids":["USN-4813-1"],"notices":[{"id":"USN-4813-1","title":"Jackson Databind vulnerabilities","summary":"Several security issues were fixed in Jackson Databind.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:47:52.369205","description":"It was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2018-11307, CVE-2019-12086, CVE-2019-12814)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\narbitrary code or other unspecified impact. (CVE-2018-12022,\nCVE-2018-12023, CVE-2018-14718, CVE-2018-14719, CVE-2018-19360,\nCVE-2018-19361, CVE-2018-19362, CVE-2019-12384, CVE-2019-14379,\nCVE-2019-14439, CVE-2019-14540, CVE-2019-16335, CVE-2019-16942,\nCVE-2019-16943, CVE-2019-17267, CVE-2019-17531, CVE-2019-20330,\nCVE-2020-10672, CVE-2020-10673, CVE-2020-10968, CVE-2020-10969,\nCVE-2020-11111, CVE-2020-11112, CVE-2020-11113, CVE-2020-11619,\nCVE-2020-11620, CVE-2020-14060, CVE-2020-14061, CVE-2020-14062,\nCVE-2020-14195, CVE-2020-8840, CVE-2020-9546, CVE-2020-9547, CVE-2020-9548)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute XML\nentity (XXE) attacks. (CVE-2018-14720)\n\nIt was discovered that Jackson Databind incorrectly handled\ndeserialization. An attacker could possibly use this issue to execute\nserver-side request forgery (SSRF). (CVE-2018-14721)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"jackson-databind","version":"2.4.2-3ubuntu0.1~esm2","description":"fast and powerful JSON library for Java -- data binding","is_source":true},{"name":"libjackson2-databind-java","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"},{"name":"libjackson2-databind-java-doc","version":"2.4.2-3ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jackson-databind","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-14540","CVE-2020-10969","CVE-2020-10673","CVE-2020-11113","CVE-2019-12814","CVE-2020-11620","CVE-2020-8840","CVE-2020-14060","CVE-2019-20330","CVE-2020-9548","CVE-2020-10968","CVE-2019-17267","CVE-2020-14061","CVE-2020-10672","CVE-2020-11111","CVE-2018-14720","CVE-2018-11307","CVE-2019-16335","CVE-2018-19362","CVE-2019-12086","CVE-2019-14379","CVE-2019-12384","CVE-2020-11619","CVE-2018-19361","CVE-2018-19360","CVE-2018-14721","CVE-2020-14062","CVE-2019-16943","CVE-2019-16942","CVE-2019-17531","CVE-2018-12023","CVE-2018-14718","CVE-2020-14195","CVE-2020-9546","CVE-2020-9547","CVE-2019-14439","CVE-2020-11112","CVE-2018-12022","CVE-2018-14719"]}]},{"id":"CVE-2018-20659","published":"2019-01-02T17:29:00","updated_at":"2025-07-11T07:40:54.095539+00:00","description":"\nAn issue was discovered in Bento4 1.5.1-627. The AP4_StcoAtom class in\nCore/Ap4StcoAtom.cpp has an attempted excessive memory allocation when\ncalled from AP4_AtomFactory::CreateAtomFromStream in\nCore/Ap4AtomFactory.cpp, as demonstrated by mp42hls.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/axiomatic-systems/Bento4/issues/350","https://www.cve.org/CVERecord?id=CVE-2018-20659"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-3574","published":"2019-01-02T15:29:00","updated_at":"2025-08-26T12:16:46.747215+00:00","description":"\nIn libsixel v1.8.2, there is a heap-based buffer over-read in the function\nload_jpeg() in the file loader.c, as demonstrated by img2sixel.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/saitoha/libsixel/issues/83","https://github.com/TeamSeri0us/pocs/tree/master/libsixel","https://www.cve.org/CVERecord?id=CVE-2019-3574"],"bugs":[""],"patches":{"libsixel":[]},"tags":{},"packages":[{"name":"libsixel","source":"https://ubuntu.com/security/cve?package=libsixel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libsixel","debian":"https://tracker.debian.org/pkg/libsixel","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.2-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-3573","published":"2019-01-02T15:29:00","updated_at":"2025-08-26T12:16:46.747215+00:00","description":"\nIn libsixel v1.8.2, there is an infinite loop in the function\nsixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by\nsixel2png.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/saitoha/libsixel/issues/83","https://github.com/TeamSeri0us/pocs/tree/master/libsixel","https://www.cve.org/CVERecord?id=CVE-2019-3573"],"bugs":[""],"patches":{"libsixel":[]},"tags":{},"packages":[{"name":"libsixel","source":"https://ubuntu.com/security/cve?package=libsixel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libsixel","debian":"https://tracker.debian.org/pkg/libsixel","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.8.2-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.8.2-2.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-3572","published":"2019-01-02T15:29:00","updated_at":"2025-08-26T12:16:46.747215+00:00","description":"\nAn issue was discovered in libming 0.4.8. There is a heap-based buffer\nover-read in the function writePNG in the file util/dbl2png.c of the\ndbl2png command-line program. Because this is associated with an erroneous\ncall to png_write_row in libpng, an out-of-bounds write might occur for\nsome memory layouts.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/libming/libming/issues/169","https://www.cve.org/CVERecord?id=CVE-2019-3572"],"bugs":[""],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-20657","published":"2019-01-02T14:29:00","updated_at":"2025-08-26T12:08:33.765930+00:00","description":"\nThe demangle_template function in cplus-dem.c in GNU libiberty, as\ndistributed in GNU Binutils 2.31.1, has a memory leak via a crafted string,\nleading to a denial of service (memory consumption), as demonstrated by\ncxxfilt, a related issue to CVE-2018-12698.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"10-byte memleak, not considered important to be fixed by\nupstream, so no patch is available as of 2025-01-09\ncode was completely removed by the following commit:\nhttps://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=1910070b298052d7ca8e4024891465824588c1e9\nspecifically the \"Remove support for demangling GCC 2.x era\nmangling schemes.\" part."}],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-20657"],"bugs":["https://gcc.gnu.org/bugzilla/show_bug.cgi?id=88539"],"patches":{"binutils":[]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-17188","published":"2019-01-02T14:29:00","updated_at":"2025-08-26T12:05:24.036876+00:00","description":"\nPrior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration\nof key components of the database. In some cases, this lead to\nvulnerabilities where CouchDB admin users could access the underlying\noperating system as the CouchDB user. Together with other vulnerabilities,\nit allowed full system entry for unauthenticated users. Rather than waiting\nfor new vulnerabilities to be discovered, and fixing them as they come up,\nthe CouchDB development team decided to make changes to avoid this entire\nclass of vulnerabilities.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2018/12/17/1","https://www.cve.org/CVERecord?id=CVE-2018-17188"],"bugs":[""],"patches":{"couchdb":[]},"tags":{},"packages":[{"name":"couchdb","source":"https://ubuntu.com/security/cve?package=couchdb","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=couchdb","debian":"https://tracker.debian.org/pkg/couchdb","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2019-3500","published":"2019-01-02T00:00:00","updated_at":"2025-08-25T23:11:45.588501+00:00","description":"\naria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic\nAuthentication username and password in a file, which might allow local\nusers to obtain sensitive information by reading this file.","ubuntu_description":"\nIt was discovered that aria2 could accidentally leak authentication data. An\nattacker could possibly use this to gain access to sensitive information.","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/aria2/aria2/issues/1329","https://github.com/aria2/aria2/commit/37368130ca7de5491a75fd18a20c5c5cc641824a","https://ubuntu.com/security/notices/USN-3965-1","https://ubuntu.com/security/notices/USN-4869-1","https://www.cve.org/CVERecord?id=CVE-2019-3500"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=918058"],"patches":{"aria2":[]},"tags":{},"packages":[{"name":"aria2","source":"https://ubuntu.com/security/cve?package=aria2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=aria2","debian":"https://tracker.debian.org/pkg/aria2","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.33.1-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1.19.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"cosmic","status":"released","description":"1.34.0-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1.34.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.34.0-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.18.1-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.34.0-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3965-1","USN-4869-1"],"notices":[{"id":"USN-3965-1","title":"aria2 vulnerability","summary":"aria2 stores authentication information in plain text.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-05-06T13:33:06.735241","description":"Dhiraj Mishra discovered that aria2 incorrectly stored authentication\ninformation. A local attacker could possibly use this issue to obtain\ncredentials.\n","is_hidden":false,"release_packages":{"cosmic":[{"name":"aria2","version":"1.34.0-2ubuntu0.1","description":"High speed command-line download utility","is_source":true},{"name":"libaria2-0","version":"1.34.0-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":"https://launchpad.net/ubuntu/+source/aria2/1.34.0-2ubuntu0.1"},{"name":"aria2","version":"1.34.0-2ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":"https://launchpad.net/ubuntu/+source/aria2/1.34.0-2ubuntu0.1"}],"disco":[{"name":"aria2","version":"1.34.0-3ubuntu0.1","description":"High speed command-line download utility","is_source":true},{"name":"libaria2-0","version":"1.34.0-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":"https://launchpad.net/ubuntu/+source/aria2/1.34.0-3ubuntu0.1"},{"name":"aria2","version":"1.34.0-3ubuntu0.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":"https://launchpad.net/ubuntu/+source/aria2/1.34.0-3ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2019-3500"]},{"id":"USN-4869-1","title":"aria2 vulnerability","summary":"aria2 could be made to expose sensitive information over the\nnetwork.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2021-03-15T22:58:32.936540","description":"It was discovered that aria2 could accidentally leak authentication data.\nAn attacker could possibly use this to gain access to sensitive information.","is_hidden":false,"release_packages":{"trusty":[{"name":"aria2","version":"1.18.1-1ubuntu0.1~esm1","description":"High speed download utility","is_source":true},{"name":"aria2","version":"1.18.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":null,"pocket":"esm-infra"}],"bionic":[{"name":"aria2","version":"1.33.1-1ubuntu0.1~esm1","description":"High speed download utility","is_source":true},{"name":"aria2","version":"1.33.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"aria2","version":"1.19.0-1ubuntu0.1~esm1","description":"High speed download utility","is_source":true},{"name":"aria2","version":"1.19.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/aria2","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-3500"]}]},{"id":"CVE-2018-20651","published":"2019-01-01T16:29:00","updated_at":"2025-08-25T22:53:02.610254+00:00","description":"\nA NULL pointer dereference was discovered in elf_link_add_object_symbols in\nelflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as\ndistributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with\nno program headers. A specially crafted ELF file allows remote attackers to\ncause a denial of service, as demonstrated by ld.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-1","https://www.cve.org/CVERecord?id=CVE-2018-20651"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=24041"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=54025d5812ff100f5f0654eb7e1ffd50f2e37f5f"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"bionic","status":"released","description":"2.30-21ubuntu1~18.04.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-1"],"notices":[{"id":"USN-4336-1","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-04-22T11:40:31.150411","description":"It was discovered that GNU binutils contained a large number of security\nissues. If a user or automated system were tricked into processing a\nspecially-crafted file, a remote attacker could cause GNU binutils to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"binutils","version":"2.30-21ubuntu1~18.04.3","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-aarch64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-alpha-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-arm-linux-gnueabi","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-arm-linux-gnueabihf","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-common","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-dev","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-doc","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-for-build","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-for-host","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-hppa-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-hppa64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-i686-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-i686-kfreebsd-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-i686-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-ia64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-m68k-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mips-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mips64-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mips64el-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsel-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsisa32r6-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsisa32r6el-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsisa64r6-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsisa64r6-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsisa64r6el-linux-gnuabi64","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-mipsisa64r6el-linux-gnuabin32","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-multiarch","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-multiarch-dev","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-powerpc-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-powerpc64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-riscv64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-s390x-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-sh4-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-source","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-sparc64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-x86-64-kfreebsd-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-x86-64-linux-gnu","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"binutils-x86-64-linux-gnux32","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"},{"name":"libbinutils","version":"2.30-21ubuntu1~18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":"https://launchpad.net/ubuntu/+source/binutils/2.30-21ubuntu1~18.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-1000876","CVE-2018-10372","CVE-2018-10373","CVE-2018-10534","CVE-2018-10535","CVE-2018-12641","CVE-2018-12697","CVE-2018-12698","CVE-2018-12699","CVE-2018-12700","CVE-2018-12934","CVE-2018-13033","CVE-2018-17358","CVE-2018-17359","CVE-2018-17360","CVE-2018-17794","CVE-2018-17985","CVE-2018-18309","CVE-2018-18483","CVE-2018-18484","CVE-2018-18605","CVE-2018-18606","CVE-2018-18607","CVE-2018-18700","CVE-2018-18701","CVE-2018-19931","CVE-2018-19932","CVE-2018-20002","CVE-2018-20623","CVE-2018-20651","CVE-2018-20671","CVE-2018-8945","CVE-2018-9138","CVE-2019-12972","CVE-2019-14250","CVE-2019-14444","CVE-2019-17450","CVE-2019-17451","CVE-2019-9070","CVE-2019-9071","CVE-2019-9073","CVE-2019-9074","CVE-2019-9075","CVE-2019-9077"]}]},{"id":"CVE-2018-20650","published":"2019-01-01T00:00:00","updated_at":"2025-08-25T22:53:02.610254+00:00","description":"\nA reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers\nto cause a denial of service due to the lack of a check for the dict data\ntype, as demonstrated by use of the FileSpec class (in FileSpec.cc) in\npdfdetach.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitlab.freedesktop.org/poppler/poppler/issues/704","https://ubuntu.com/security/notices/USN-3865-1","https://www.cve.org/CVERecord?id=CVE-2018-20650"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=917974"],"patches":{"poppler":["upstream: https://gitlab.freedesktop.org/poppler/poppler/commit/de0c0b8324e776f0b851485e0fc9622fc35695b7"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"bionic","status":"released","description":"0.62.0-2ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.15","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.68.0-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.11","component":null,"pocket":"security"}]}],"notices_ids":["USN-3865-1"],"notices":[{"id":"USN-3865-1","title":"poppler vulnerabilities","summary":"Several security issues were fixed in poppler.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-01-22T13:58:23.680320","description":"It was discovered that poppler incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2018-20481, CVE-2018-20650)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.6","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.6","pocket":"security"}],"cosmic":[{"name":"poppler","version":"0.68.0-0ubuntu1.4","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-cpp-dev","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-cpp0v5","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-dev","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-glib-dev","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-glib-doc","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-glib8","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-private-dev","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-qt5-1","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler-qt5-dev","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"libpoppler79","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"},{"name":"poppler-utils","version":"0.68.0-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.4"}],"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.15","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.15","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.11","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-20481","CVE-2018-20650"]}]},{"id":"CVE-2018-6340","published":"2018-12-31T22:29:00","updated_at":"2025-08-26T12:09:34.955868+00:00","description":"\nThe Memcache::getextendedstats function can be used to trigger an\nout-of-bounds read. Exploiting this issue requires control over memcached\nserver hostnames and/or ports. This affects all supported versions of HHVM\n(3.30 and 3.27.4 and below).","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/facebook/hhvm/commit/4bff3bfbe90d10451e4638c2118d1ad1117bb3e3","https://hhvm.com/blog/2018/12/18/hhvm-3.30.1.html","https://www.cve.org/CVERecord?id=CVE-2018-6340"],"bugs":[""],"patches":{"hhvm":[]},"tags":{},"packages":[{"name":"hhvm","source":"https://ubuntu.com/security/cve?package=hhvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hhvm","debian":"https://tracker.debian.org/pkg/hhvm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":50740,"limit":20,"total_results":79316}