{"cves":[{"id":"CVE-2018-19535","published":"2018-11-25T00:00:00","updated_at":"2025-08-25T22:51:48.884347+00:00","description":"\nIn Exiv2 0.26 and previous versions, PngChunk::readRawProfile in\npngchunk_int.cpp may cause a denial of service (application crash due to a\nheap-based buffer over-read) via a crafted PNG file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"1-byte invalid read"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Exiv2/exiv2/pull/430","https://ubuntu.com/security/notices/USN-4056-1","https://www.cve.org/CVERecord?id=CVE-2018-19535"],"bugs":["https://github.com/Exiv2/exiv2/issues/428","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=915135"],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"released","description":"0.25-3.1ubuntu0.18.04.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.25-4ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.25-4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.27-RC1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.25-2.1ubuntu16.04.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-4056-1"],"notices":[{"id":"USN-4056-1","title":"Exiv2 vulnerabilities","summary":"Several security issues were fixed in Exiv2.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-07-15T13:25:13.484047","description":"It was discovered that Exiv2 incorrectly handled certain PSD files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2018-19107, CVE-2018-19108)\n\nIt was discovered that Exiv2 incorrectly handled certain PNG files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2018-19535, CVE-2019-13112)\n\nIt was discovered that Exiv2 incorrectly handled certain CRW files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2019-13110, CVE-2019-13113)\n\nIt was discovered that incorrectly handled certain HTTP requests.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2019-13114)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.3","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.3","pocket":"security"},{"name":"libexiv2-14","version":"0.25-3.1ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.3","pocket":"security"},{"name":"libexiv2-dev","version":"0.25-3.1ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.3","pocket":"security"},{"name":"libexiv2-doc","version":"0.25-3.1ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-3.1ubuntu0.18.04.3","pocket":"security"}],"cosmic":[{"name":"exiv2","version":"0.25-4ubuntu0.2","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-4ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu0.2"},{"name":"libexiv2-14","version":"0.25-4ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu0.2"},{"name":"libexiv2-dev","version":"0.25-4ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu0.2"},{"name":"libexiv2-doc","version":"0.25-4ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu0.2"}],"disco":[{"name":"exiv2","version":"0.25-4ubuntu1.1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-4ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu1.1"},{"name":"libexiv2-14","version":"0.25-4ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu1.1"},{"name":"libexiv2-dev","version":"0.25-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu1.1"},{"name":"libexiv2-doc","version":"0.25-4ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-4ubuntu1.1"}],"xenial":[{"name":"exiv2","version":"0.25-2.1ubuntu16.04.4","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-2.1ubuntu16.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-2.1ubuntu16.04.4","pocket":"security"},{"name":"libexiv2-14","version":"0.25-2.1ubuntu16.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-2.1ubuntu16.04.4","pocket":"security"},{"name":"libexiv2-dev","version":"0.25-2.1ubuntu16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-2.1ubuntu16.04.4","pocket":"security"},{"name":"libexiv2-doc","version":"0.25-2.1ubuntu16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.25-2.1ubuntu16.04.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19107","CVE-2018-19108","CVE-2018-19535","CVE-2019-13110","CVE-2019-13112","CVE-2019-13113","CVE-2019-13114"]}]},{"id":"CVE-2018-19517","published":"2018-11-24T18:29:00","updated_at":"2025-08-25T22:51:48.884347+00:00","description":"\nAn issue was discovered in sysstat 12.1.1. The remap_struct function in\nsa_common.c has an out-of-bounds read during a memset call, as demonstrated\nby sadf.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19517"],"bugs":["https://github.com/sysstat/sysstat/issues/199","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914553"],"patches":{"sysstat":["upstream: https://github.com/sysstat/sysstat/commit/fbc691eaaa10d0bcea6741d5a223dc3906106548"]},"tags":{},"packages":[{"name":"sysstat","source":"https://ubuntu.com/security/cve?package=sysstat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sysstat","debian":"https://tracker.debian.org/pkg/sysstat","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"12.0.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19504","published":"2018-11-23T19:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nAn issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1.\nThere is a NULL pointer dereference in ifilter_bank() in\nlibfaad/filtbank.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/faac/bugs/240/","https://github.com/TeamSeri0us/pocs/tree/master/faad","https://www.cve.org/CVERecord?id=CVE-2018-19504"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914641"],"patches":{"faad2":[]},"tags":{},"packages":[{"name":"faad2","source":"https://ubuntu.com/security/cve?package=faad2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=faad2","debian":"https://tracker.debian.org/pkg/faad2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19503","published":"2018-11-23T19:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nAn issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1.\nThere was a stack-based buffer overflow in the function calculate_gain() in\nlibfaad/sbr_hfadj.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/faac/bugs/240/","https://github.com/TeamSeri0us/pocs/tree/master/faad","https://www.cve.org/CVERecord?id=CVE-2018-19503"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914641"],"patches":{"faad2":[]},"tags":{},"packages":[{"name":"faad2","source":"https://ubuntu.com/security/cve?package=faad2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=faad2","debian":"https://tracker.debian.org/pkg/faad2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19502","published":"2018-11-23T19:29:00","updated_at":"2025-08-18T17:08:00.281595+00:00","description":"\nAn issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1.\nThere was a heap-based buffer overflow in the function excluded_channels()\nin libfaad/syntax.c.","ubuntu_description":"\nIt was discovered that Freeware Advanced Audio Decoder 2 incorrectly\nhandled certain mp4 files. An attacker could possibly use this issue\nto cause a denial of service.","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/faac/bugs/240/","https://github.com/TeamSeri0us/pocs/tree/master/faad","https://www.cve.org/CVERecord?id=CVE-2018-19502"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914641"],"patches":{"faad2":[]},"tags":{},"packages":[{"name":"faad2","source":"https://ubuntu.com/security/cve?package=faad2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=faad2","debian":"https://tracker.debian.org/pkg/faad2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.7-8+deb8u3build0.14.04.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"impish","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.8.8-3.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19492","published":"2018-11-23T17:29:00","updated_at":"2025-10-03T10:51:13.124146+00:00","description":"\nAn issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an\nattacker to conduct a buffer overflow with an arbitrary amount of data in\nthe cairotrm_options function. This flaw is caused by a missing size check\nof an argument passed to the \"set font\" function. This issue occurs when\nthe Gnuplot pngcairo terminal is used as a backend.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/gnuplot/bugs/2089/","https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/","https://ubuntu.com/security/notices/USN-4541-1","https://www.cve.org/CVERecord?id=CVE-2018-19492","https://ubuntu.com/security/notices/USN-7589-1"],"bugs":[""],"patches":{"gnuplot5":[],"gnuplot":[]},"tags":{},"packages":[{"name":"gnuplot5","source":"https://ubuntu.com/security/cve?package=gnuplot5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnuplot5","debian":"https://tracker.debian.org/pkg/gnuplot5","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gnuplot","source":"https://ubuntu.com/security/cve?package=gnuplot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnuplot","debian":"https://tracker.debian.org/pkg/gnuplot","statuses":[{"release_codename":"xenial","status":"released","description":"4.6.6-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.4.2+dfsg2-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.2.8+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.0.0+dfsg1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.0.0+dfsg1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.0.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"5.2.2+dfsg1-2ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"released","description":"4.6.4-2ubuntu0.1~esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"not-affected","description":"6.0.2+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.0.2+dfsg1-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4541-1","USN-7589-1"],"notices":[{"id":"USN-4541-1","title":"Gnuplot vulnerabilities","summary":"Several security issues were fixed in Gnuplot.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-25T17:14:48.527326","description":"Tim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the\ndf_generate_ascii_array_entry function. An attacker could possibly use\nthis issue to cause a heap buffer overflow, resulting in a denial of \nservice attack or arbitrary code execution. (CVE-2018-19490)\n\nTim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the \nPS_options function when the Gnuplot postscript terminal is used as a \nbackend. An attacker could possibly use this issue to cause a buffer\noverflow, resulting in a denial of service attack or arbitrary code \nexecution. (CVE-2018-19491)\n\nTim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the \ncairotrm_options function when the Gnuplot postscript terminal is used as\na backend. An attacker could possibly use this issue to cause a buffer\noverflow, resulting in a denial of service attack or arbitrary code \nexecution. (CVE-2018-19492)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"gnuplot","version":"4.6.6-3ubuntu0.1","description":"Command-line driven interactive plotting program","is_source":true},{"name":"gnuplot","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-data","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-doc","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-nox","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-qt","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-tex","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-x11","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19490","CVE-2018-19491","CVE-2018-19492"]},{"id":"USN-7589-1","title":"Gnuplot vulnerabilities","summary":"Several security issues were fixed in Gnuplot.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2025-06-23T12:12:04.386657","description":"Tim Blazytko, Cornelius Aschermann, Sergej Schumilo, and Nils Bars\ndiscovered that Gnuplot had several memory-related issues. An\nattacker could possibly use these issues to cause Gnuplot to\nexperience a buffer overflow, resulting in a denial of service or\narbitrary code execution. These issues only affected Ubuntu\n14.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-19490, CVE-2018-19491,\nCVE-2018-19492)\n\nIt was discovered that Gnuplot could write out-of-bounds due to\nthe use of strncpy(). An attacker could possibly use this issue\nto enable the execution of arbitrary code. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-25412)\n\nIt was discovered that Gnuplot incorrectly freed memory when\nexecuting print_set_output(). An attacker could possibly use this\nissue to enable the execution of arbitrary code. (CVE-2020-25559)\n\nIt was discovered that Gnuplot's plotrequest() function contained\na buffer overflow. An attacker could possibly use this issue to\ncause Gnuplot to crash, resulting in a denial of service or\narbitrary code execution. (CVE-2020-25969)\n\nIt was discovered that Gnuplot's boundary3d() function could be\nmade to divide by zero. An attacker could possibly use this issue\nto cause Gnuplot to crash, resulting in a denial of service.\n(CVE-2021-44917)","is_hidden":false,"release_packages":{"bionic":[{"name":"gnuplot","version":"5.2.2+dfsg1-2ubuntu1+esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"gnuplot","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"gnuplot","version":"4.6.4-2ubuntu0.1~esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-doc","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-nox","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-qt","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-x11","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"gnuplot","version":"4.6.6-3ubuntu0.1+esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-tex","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-25969","CVE-2018-19492","CVE-2018-19490","CVE-2020-25412","CVE-2018-19491","CVE-2020-25559","CVE-2021-44917"]}]},{"id":"CVE-2018-19491","published":"2018-11-23T17:29:00","updated_at":"2025-10-03T10:51:13.124146+00:00","description":"\nAn issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an\nattacker to conduct a buffer overflow with an arbitrary amount of data in\nthe PS_options function. This flaw is caused by a missing size check of an\nargument passed to the \"set font\" function. This issue occurs when the\nGnuplot postscript terminal is used as a backend.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/gnuplot/bugs/2094/","https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/","https://ubuntu.com/security/notices/USN-4541-1","https://www.cve.org/CVERecord?id=CVE-2018-19491","https://ubuntu.com/security/notices/USN-7589-1"],"bugs":[""],"patches":{"gnuplot5":[],"gnuplot":[]},"tags":{},"packages":[{"name":"gnuplot5","source":"https://ubuntu.com/security/cve?package=gnuplot5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnuplot5","debian":"https://tracker.debian.org/pkg/gnuplot5","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gnuplot","source":"https://ubuntu.com/security/cve?package=gnuplot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnuplot","debian":"https://tracker.debian.org/pkg/gnuplot","statuses":[{"release_codename":"xenial","status":"released","description":"4.6.6-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.4.2+dfsg2-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.2.8+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.0.0+dfsg1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.0.0+dfsg1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.0.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"5.2.2+dfsg1-2ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"released","description":"4.6.4-2ubuntu0.1~esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"not-affected","description":"6.0.2+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.0.2+dfsg1-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4541-1","USN-7589-1"],"notices":[{"id":"USN-4541-1","title":"Gnuplot vulnerabilities","summary":"Several security issues were fixed in Gnuplot.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-25T17:14:48.527326","description":"Tim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the\ndf_generate_ascii_array_entry function. An attacker could possibly use\nthis issue to cause a heap buffer overflow, resulting in a denial of \nservice attack or arbitrary code execution. (CVE-2018-19490)\n\nTim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the \nPS_options function when the Gnuplot postscript terminal is used as a \nbackend. An attacker could possibly use this issue to cause a buffer\noverflow, resulting in a denial of service attack or arbitrary code \nexecution. (CVE-2018-19491)\n\nTim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the \ncairotrm_options function when the Gnuplot postscript terminal is used as\na backend. An attacker could possibly use this issue to cause a buffer\noverflow, resulting in a denial of service attack or arbitrary code \nexecution. (CVE-2018-19492)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"gnuplot","version":"4.6.6-3ubuntu0.1","description":"Command-line driven interactive plotting program","is_source":true},{"name":"gnuplot","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-data","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-doc","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-nox","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-qt","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-tex","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-x11","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19490","CVE-2018-19491","CVE-2018-19492"]},{"id":"USN-7589-1","title":"Gnuplot vulnerabilities","summary":"Several security issues were fixed in Gnuplot.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2025-06-23T12:12:04.386657","description":"Tim Blazytko, Cornelius Aschermann, Sergej Schumilo, and Nils Bars\ndiscovered that Gnuplot had several memory-related issues. An\nattacker could possibly use these issues to cause Gnuplot to\nexperience a buffer overflow, resulting in a denial of service or\narbitrary code execution. These issues only affected Ubuntu\n14.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-19490, CVE-2018-19491,\nCVE-2018-19492)\n\nIt was discovered that Gnuplot could write out-of-bounds due to\nthe use of strncpy(). An attacker could possibly use this issue\nto enable the execution of arbitrary code. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-25412)\n\nIt was discovered that Gnuplot incorrectly freed memory when\nexecuting print_set_output(). An attacker could possibly use this\nissue to enable the execution of arbitrary code. (CVE-2020-25559)\n\nIt was discovered that Gnuplot's plotrequest() function contained\na buffer overflow. An attacker could possibly use this issue to\ncause Gnuplot to crash, resulting in a denial of service or\narbitrary code execution. (CVE-2020-25969)\n\nIt was discovered that Gnuplot's boundary3d() function could be\nmade to divide by zero. An attacker could possibly use this issue\nto cause Gnuplot to crash, resulting in a denial of service.\n(CVE-2021-44917)","is_hidden":false,"release_packages":{"bionic":[{"name":"gnuplot","version":"5.2.2+dfsg1-2ubuntu1+esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"gnuplot","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"gnuplot","version":"4.6.4-2ubuntu0.1~esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-doc","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-nox","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-qt","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-x11","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"gnuplot","version":"4.6.6-3ubuntu0.1+esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-tex","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-25969","CVE-2018-19492","CVE-2018-19490","CVE-2020-25412","CVE-2018-19491","CVE-2020-25559","CVE-2021-44917"]}]},{"id":"CVE-2018-19490","published":"2018-11-23T17:29:00","updated_at":"2025-10-03T10:51:18.109312+00:00","description":"\nAn issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows\nan attacker to conduct a heap-based buffer overflow with an arbitrary\namount of data in df_generate_ascii_array_entry. To exploit this\nvulnerability, an attacker must pass an overlong string as the right bound\nof the range argument that is passed to the plot function.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/gnuplot/bugs/2093/","https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/","https://ubuntu.com/security/notices/USN-4541-1","https://www.cve.org/CVERecord?id=CVE-2018-19490","https://ubuntu.com/security/notices/USN-7589-1"],"bugs":[""],"patches":{"gnuplot5":[],"gnuplot":[]},"tags":{},"packages":[{"name":"gnuplot5","source":"https://ubuntu.com/security/cve?package=gnuplot5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnuplot5","debian":"https://tracker.debian.org/pkg/gnuplot5","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gnuplot","source":"https://ubuntu.com/security/cve?package=gnuplot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnuplot","debian":"https://tracker.debian.org/pkg/gnuplot","statuses":[{"release_codename":"xenial","status":"released","description":"4.6.6-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.2.8+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"5.2.2+dfsg1-2ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.4.2+dfsg2-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.0.0+dfsg1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.0.0+dfsg1-1ubuntu3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.0.2+dfsg1-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.0.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.6.4-2ubuntu0.1~esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"not-affected","description":"6.0.2+dfsg1-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4541-1","USN-7589-1"],"notices":[{"id":"USN-4541-1","title":"Gnuplot vulnerabilities","summary":"Several security issues were fixed in Gnuplot.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-25T17:14:48.527326","description":"Tim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the\ndf_generate_ascii_array_entry function. An attacker could possibly use\nthis issue to cause a heap buffer overflow, resulting in a denial of \nservice attack or arbitrary code execution. (CVE-2018-19490)\n\nTim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the \nPS_options function when the Gnuplot postscript terminal is used as a \nbackend. An attacker could possibly use this issue to cause a buffer\noverflow, resulting in a denial of service attack or arbitrary code \nexecution. (CVE-2018-19491)\n\nTim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars \ndiscovered that Gnuplot did not properly validate string sizes in the \ncairotrm_options function when the Gnuplot postscript terminal is used as\na backend. An attacker could possibly use this issue to cause a buffer\noverflow, resulting in a denial of service attack or arbitrary code \nexecution. (CVE-2018-19492)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"gnuplot","version":"4.6.6-3ubuntu0.1","description":"Command-line driven interactive plotting program","is_source":true},{"name":"gnuplot","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-data","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-doc","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-nox","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-qt","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-tex","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"},{"name":"gnuplot-x11","version":"4.6.6-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":"https://launchpad.net/ubuntu/+source/gnuplot/4.6.6-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19490","CVE-2018-19491","CVE-2018-19492"]},{"id":"USN-7589-1","title":"Gnuplot vulnerabilities","summary":"Several security issues were fixed in Gnuplot.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2025-06-23T12:12:04.386657","description":"Tim Blazytko, Cornelius Aschermann, Sergej Schumilo, and Nils Bars\ndiscovered that Gnuplot had several memory-related issues. An\nattacker could possibly use these issues to cause Gnuplot to\nexperience a buffer overflow, resulting in a denial of service or\narbitrary code execution. These issues only affected Ubuntu\n14.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-19490, CVE-2018-19491,\nCVE-2018-19492)\n\nIt was discovered that Gnuplot could write out-of-bounds due to\nthe use of strncpy(). An attacker could possibly use this issue\nto enable the execution of arbitrary code. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-25412)\n\nIt was discovered that Gnuplot incorrectly freed memory when\nexecuting print_set_output(). An attacker could possibly use this\nissue to enable the execution of arbitrary code. (CVE-2020-25559)\n\nIt was discovered that Gnuplot's plotrequest() function contained\na buffer overflow. An attacker could possibly use this issue to\ncause Gnuplot to crash, resulting in a denial of service or\narbitrary code execution. (CVE-2020-25969)\n\nIt was discovered that Gnuplot's boundary3d() function could be\nmade to divide by zero. An attacker could possibly use this issue\nto cause Gnuplot to crash, resulting in a denial of service.\n(CVE-2021-44917)","is_hidden":false,"release_packages":{"bionic":[{"name":"gnuplot","version":"5.2.2+dfsg1-2ubuntu1+esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"5.2.2+dfsg1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"gnuplot","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"5.2.8+dfsg1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"gnuplot","version":"4.6.4-2ubuntu0.1~esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-doc","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-nox","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-qt","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnuplot-x11","version":"4.6.4-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"gnuplot","version":"4.6.6-3ubuntu0.1+esm1","description":"A portable command-line driven graphing utility.","is_source":true},{"name":"gnuplot","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-data","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-doc","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-nox","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-qt","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-tex","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"},{"name":"gnuplot-x11","version":"4.6.6-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnuplot","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-25969","CVE-2018-19492","CVE-2018-19490","CVE-2020-25412","CVE-2018-19491","CVE-2020-25559","CVE-2021-44917"]}]},{"id":"CVE-2018-19486","published":"2018-11-23T00:00:00","updated_at":"2025-08-25T22:51:44.236397+00:00","description":"\nGit before 2.19.2 on Linux and UNIX executes commands from the current\nworking directory (as if '.' were at the end of $PATH) in certain cases\ninvolving the run_command() API and run-command.c, because there was a\ndangerous change from execvp to execv during 2017.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://git.kernel.org/pub/scm/git/git.git/tree/Documentation/RelNotes/2.19.2.txt","https://ubuntu.com/security/notices/USN-3829-1","https://www.cve.org/CVERecord?id=CVE-2018-19486"],"bugs":[""],"patches":{"git":["upstream: https://git.kernel.org/pub/scm/git/git.git/commit/?id=321fd82389742398d2924640ce3a61791fd27d60"]},"tags":{},"packages":[{"name":"git","source":"https://ubuntu.com/security/cve?package=git","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=git","debian":"https://tracker.debian.org/pkg/git","statuses":[{"release_codename":"bionic","status":"released","description":"1:2.17.1-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:2.19.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:2.19.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3829-1"],"notices":[{"id":"USN-3829-1","title":"Git vulnerabilities","summary":"Several security issues were fixed in Git.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-11-27T18:59:44.300191","description":"It was discovered that Git incorrectly handled layers of tree objects.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2017-15298)\n\nIt was discovered that Git incorrectly handled certain inputs.\nAn attacker could possibly use this issue to execute arbitrary code.\nThis issue only affected Ubuntu 18.04 LTS and Ubuntu 18.10.\n(CVE-2018-19486)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"git","version":"1:2.17.1-1ubuntu0.4","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-all","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-cvs","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-daemon-run","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-daemon-sysvinit","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-doc","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-el","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-email","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-gui","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-man","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-mediawiki","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"git-svn","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"gitk","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"},{"name":"gitweb","version":"1:2.17.1-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.4","pocket":"security"}],"cosmic":[{"name":"git","version":"1:2.19.1-1ubuntu1.1","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:2.19.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.19.1-1ubuntu1.1"}],"trusty":[{"name":"git","version":"1:1.9.1-1ubuntu0.10","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-all","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-arch","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-bzr","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-core","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-cvs","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-daemon-run","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-daemon-sysvinit","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-doc","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-el","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-email","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-gui","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-man","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-mediawiki","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"git-svn","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"gitk","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"},{"name":"gitweb","version":"1:1.9.1-1ubuntu0.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:1.9.1-1ubuntu0.10","pocket":"security"}],"xenial":[{"name":"git","version":"1:2.7.4-0ubuntu1.6","description":"fast, scalable, distributed revision control system","is_source":true},{"name":"git","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-all","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-arch","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-core","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-cvs","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-daemon-run","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-daemon-sysvinit","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-doc","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-el","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-email","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-gui","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-man","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-mediawiki","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"git-svn","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"gitk","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"},{"name":"gitweb","version":"1:2.7.4-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/git","version_link":"https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-15298","CVE-2018-19486"]}]},{"id":"CVE-2018-19477","published":"2018-11-23T00:00:00","updated_at":"2025-08-25T22:51:44.236397+00:00","description":"\npsi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to\nbypass intended access restrictions because of a JBIG2Decode type\nconfusion.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26","https://ubuntu.com/security/notices/USN-3831-1","https://www.cve.org/CVERecord?id=CVE-2018-19477"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=700168"],"patches":{"ghostscript":["upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=ef252e7dc214bcbd9a2539216aab9202848602bb","upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=606a22e77e7f081781e99e44644cd0119f559e03"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"9.26~dfsg+0-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.26~dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3831-1"],"notices":[{"id":"USN-3831-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2018-11-29T13:01:30.772214","description":"It was discovered that Ghostscript contained multiple security issues. If a\nuser or automated system were tricked into processing a specially crafted\nfile, a remote attacker could possibly use these issues to access arbitrary\nfiles, execute arbitrary code, or cause a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"}],"trusty":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19409","CVE-2018-19475","CVE-2018-19476","CVE-2018-19477"]}]},{"id":"CVE-2018-19476","published":"2018-11-23T00:00:00","updated_at":"2025-08-25T22:51:44.236397+00:00","description":"\npsi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to\nbypass intended access restrictions because of a setcolorspace type\nconfusion.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26","https://ubuntu.com/security/notices/USN-3831-1","https://www.cve.org/CVERecord?id=CVE-2018-19476"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=700169"],"patches":{"ghostscript":["upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=67d760ab775dae4efe803b5944b0439aa3c0b04a","upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=434753adbe8be5534bfb9b7d91746023e8073d16"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"trusty","status":"released","description":"9.26~dfsg+0-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.26~dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3831-1"],"notices":[{"id":"USN-3831-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2018-11-29T13:01:30.772214","description":"It was discovered that Ghostscript contained multiple security issues. If a\nuser or automated system were tricked into processing a specially crafted\nfile, a remote attacker could possibly use these issues to access arbitrary\nfiles, execute arbitrary code, or cause a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"}],"trusty":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19409","CVE-2018-19475","CVE-2018-19476","CVE-2018-19477"]}]},{"id":"CVE-2018-19475","published":"2018-11-23T00:00:00","updated_at":"2025-08-25T22:51:44.236397+00:00","description":"\npsi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers\nto bypass intended access restrictions because available stack space is not\nchecked when the device remains the same.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26","https://ubuntu.com/security/notices/USN-3831-1","https://www.cve.org/CVERecord?id=CVE-2018-19475"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=700153"],"patches":{"ghostscript":["upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=3005fcb9bb160af199e761e03bc70a9f249a987e","upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=aeea342904978c9fe17d85f4906a0f6fcce2d315"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.26~dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"9.26~dfsg+0-0ubuntu0.14.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3831-1"],"notices":[{"id":"USN-3831-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2018-11-29T13:01:30.772214","description":"It was discovered that Ghostscript contained multiple security issues. If a\nuser or automated system were tricked into processing a specially crafted\nfile, a remote attacker could possibly use these issues to access arbitrary\nfiles, execute arbitrary code, or cause a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"}],"trusty":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19409","CVE-2018-19475","CVE-2018-19476","CVE-2018-19477"]}]},{"id":"CVE-2018-19443","published":"2018-11-22T19:29:00","updated_at":"2025-07-11T07:40:40.283420+00:00","description":"\nThe client in Tryton 5.x before 5.0.1 tries to make a connection to the bus\nin cleartext instead of encrypted under certain circumstances in bus.py and\njsonrpc.py. This connection attempt fails, but it contains in the header\nthe current session of the user. This session could then be stolen by a\nman-in-the-middle.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://discuss.tryton.org/t/security-release-for-issue7792/830","https://bugs.tryton.org/issue7792","https://www.cve.org/CVERecord?id=CVE-2018-19443"],"bugs":[""],"patches":{"tryton-client":[]},"tags":{},"packages":[{"name":"tryton-client","source":"https://ubuntu.com/security/cve?package=tryton-client","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tryton-client","debian":"https://tracker.debian.org/pkg/tryton-client","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects 5.x, vulnerable 5.0.0 version never in Debian","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-4386","published":"2018-11-22T00:00:00","updated_at":"2025-08-25T22:55:08.062836+00:00","description":"\nMultiple memory corruption issues were addressed with improved memory\nhandling. This issue affected versions prior to iOS 12.1, tvOS 12.1,\nwatchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0008.html","https://ubuntu.com/security/notices/USN-3828-1","https://www.cve.org/CVERecord?id=CVE-2018-4386"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.22.4-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.22.4-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3828-1"],"notices":[{"id":"USN-3828-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-11-27T18:10:44.339116","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"webkit2gtk","version":"2.22.4-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"webkit2gtk","version":"2.22.4-0ubuntu0.18.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.4-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.4-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.10.1"}]},"type":"USN","cves_ids":["CVE-2018-4345","CVE-2018-4372","CVE-2018-4386"]}]},{"id":"CVE-2018-4372","published":"2018-11-22T00:00:00","updated_at":"2025-08-25T22:55:03.672360+00:00","description":"\nMultiple memory corruption issues were addressed with improved memory\nhandling. This issue affected versions prior to iOS 12.1, tvOS 12.1,\nwatchOS 5.1, Safari 12.0.1, iTunes 12.9.1, iCloud for Windows 7.8.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0008.html","https://ubuntu.com/security/notices/USN-3828-1","https://www.cve.org/CVERecord?id=CVE-2018-4372"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.22.4-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.22.4-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.4","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.22.4-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3828-1"],"notices":[{"id":"USN-3828-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-11-27T18:10:44.339116","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"webkit2gtk","version":"2.22.4-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"webkit2gtk","version":"2.22.4-0ubuntu0.18.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.4-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.4-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.10.1"}]},"type":"USN","cves_ids":["CVE-2018-4345","CVE-2018-4372","CVE-2018-4386"]}]},{"id":"CVE-2018-4345","published":"2018-11-22T00:00:00","updated_at":"2025-08-25T22:55:03.672360+00:00","description":"\nA cross-site scripting issue existed in Safari. This issue was addressed\nwith improved URL validation. This issue affected versions prior to iOS 12,\ntvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0008.html","https://ubuntu.com/security/notices/USN-3828-1","https://www.cve.org/CVERecord?id=CVE-2018-4345"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.22.4-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"2.22.4-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.22.3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.22.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3828-1"],"notices":[{"id":"USN-3828-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-11-27T18:10:44.339116","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"webkit2gtk","version":"2.22.4-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.22.4-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"webkit2gtk","version":"2.22.4-0ubuntu0.18.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.22.4-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.22.4-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.22.4-0ubuntu0.18.10.1"}]},"type":"USN","cves_ids":["CVE-2018-4345","CVE-2018-4372","CVE-2018-4386"]}]},{"id":"CVE-2018-19432","published":"2018-11-22T00:00:00","updated_at":"2025-08-25T22:51:39.300474+00:00","description":"\nAn issue was discovered in libsndfile 1.0.28. There is a NULL pointer\ndereference in the function sf_write_int in sndfile.c, which will lead to a\ndenial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"in Check-MAX_CHANNELS-in-sndfile-deinterleave.patch patch in\ndisco+"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4013-1","https://ubuntu.com/security/notices/USN-4704-1","https://www.cve.org/CVERecord?id=CVE-2018-19432"],"bugs":["https://github.com/erikd/libsndfile/issues/427"],"patches":{"libsndfile":["upstream: https://github.com/erikd/libsndfile/commit/aaea680337267bfb6d2544da878890ee7f1c5077"]},"tags":{},"packages":[{"name":"libsndfile","source":"https://ubuntu.com/security/cve?package=libsndfile","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libsndfile","debian":"https://tracker.debian.org/pkg/libsndfile","statuses":[{"release_codename":"bionic","status":"released","description":"1.0.28-4ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.28-4ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.25-10ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.25-7ubuntu2.2+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4013-1","USN-4704-1"],"notices":[{"id":"USN-4013-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2019-06-10T14:08:57.040401","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.04.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.10.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.2","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14245","CVE-2017-14246","CVE-2017-14634","CVE-2017-16942","CVE-2017-17456","CVE-2017-17457","CVE-2017-6892","CVE-2018-13139","CVE-2018-19432","CVE-2018-19661","CVE-2018-19662","CVE-2018-19758","CVE-2019-3832"]},{"id":"USN-4704-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2021-01-26T16:23:13.203532","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-12562)\n\nIt was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-14245,\nCVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892,\nCVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662,\nCVE-2018-19758, CVE-2019-3832)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libsndfile","version":"1.0.25-7ubuntu2.2+esm1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"libsndfile1-dev","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"sndfile-programs","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.3","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12562","CVE-2018-19758","CVE-2018-19661","CVE-2017-16942","CVE-2017-6892","CVE-2018-19432","CVE-2018-19662","CVE-2017-14246","CVE-2017-14634","CVE-2019-3832","CVE-2018-13139","CVE-2017-14245"]}]},{"id":"CVE-2018-19416","published":"2018-11-21T20:29:00","updated_at":"2025-08-25T22:51:39.300474+00:00","description":"\nAn issue was discovered in sysstat 12.1.1. The remap_struct function in\nsa_common.c has an out-of-bounds read during a memmove call, as\ndemonstrated by sadf.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19416"],"bugs":["https://github.com/sysstat/sysstat/issues/196","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914384"],"patches":{"sysstat":["upstream: https://github.com/sysstat/sysstat/commit/fbc691eaaa10d0bcea6741d5a223dc3906106548"]},"tags":{},"packages":[{"name":"sysstat","source":"https://ubuntu.com/security/cve?package=sysstat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sysstat","debian":"https://tracker.debian.org/pkg/sysstat","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"12.0.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19406","published":"2018-11-21T00:29:00","updated_at":"2026-07-04T07:46:10.841036+00:00","description":"\nkvm_pv_send_ipi in arch/x86/kvm/lapic.c in the Linux kernel through 4.19.2\nallows local users to cause a denial of service (NULL pointer dereference\nand BUG) via crafted system calls that reach a situation where the apic map\nis uninitialized.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lore.kernel.org/lkml/1542677970-5627-1-git-send-email-wanpengli@tencent.com/","https://www.cve.org/CVERecord?id=CVE-2018-19406"],"bugs":[""],"patches":{"linux":["break-fix: 4180bf1b655a791a0a6ef93a2ffffc762722c782 38ab012f109caf10f471db1adf284e620dd8d701"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-20.21","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-16.19","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1007.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1009.9","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1009.9","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.18.0-1005.5~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1006.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.18.0-12.13~18.04.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.18.0-12.13~18.04.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1008.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1004.9","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1010.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19409","published":"2018-11-21T00:00:00","updated_at":"2025-08-25T22:51:39.300474+00:00","description":"\nAn issue was discovered in Artifex Ghostscript before 9.26.\nLockSafetyParams is not checked correctly if another device is used.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.ghostscript.com/doc/9.26/History9.htm#Version9.26","https://ubuntu.com/security/notices/USN-3831-1","https://www.cve.org/CVERecord?id=CVE-2018-19409"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=700176"],"patches":{"ghostscript":["upstream: https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=661e8d8fb8248c38d67958beda32f3a5876d0c3f"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"bionic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"9.26~dfsg+0-0ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"9.26~dfsg+0-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.26~dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.26~dfsg+0-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3831-1"],"notices":[{"id":"USN-3831-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2018-11-29T13:01:30.772214","description":"It was discovered that Ghostscript contained multiple security issues. If a\nuser or automated system were tricked into processing a specially crafted\nfile, a remote attacker could possibly use these issues to access arbitrary\nfiles, execute arbitrary code, or cause a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.18.10.1"}],"trusty":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.26~dfsg+0-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.26~dfsg+0-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19409","CVE-2018-19475","CVE-2018-19476","CVE-2018-19477"]}]}],"offset":51160,"limit":20,"total_results":79316}