{"cves":[{"id":"CVE-2018-19200","published":"2018-11-12T15:29:00","updated_at":"2025-08-25T22:51:34.744515+00:00","description":"\nAn issue was discovered in uriparser before 0.9.0. UriCommon.c allows\nattempted operations on NULL input via a uriResetUri* function.","ubuntu_description":"\nIt was discovered that uriparser mishandled certain input. An attacker could\nuse this vulnerability to cause uriparser to crash or possibly execute\narbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/uriparser/uriparser/commit/f58c25069cf4a986fe17a80c5b38687e31feb539","https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog","https://ubuntu.com/security/notices/USN-5172-1","https://www.cve.org/CVERecord?id=CVE-2018-19200","https://ubuntu.com/security/notices/USN-5172-2"],"bugs":[""],"patches":{"uriparser":[]},"tags":{},"packages":[{"name":"uriparser","source":"https://ubuntu.com/security/cve?package=uriparser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=uriparser","debian":"https://tracker.debian.org/pkg/uriparser","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.8.4-1+deb9u2build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.9.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.7.5-1ubuntu2+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"0.9.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.4-1ubuntu0.16.04.1~esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-5172-1","USN-5172-2"],"notices":[{"id":"USN-5172-1","title":"uriparser vulnerabilities","summary":"Several security issues were fixed in uriparser.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-06T12:53:01.218019","description":"It was discovered that uriparser mishandled certain input. An attacker\ncould use this vulnerability to cause uriparser to crash or possibly\nexecute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)\n\nIt was discovered that uriparser incorrectly handled certain URIs. An\nattacker could use this vulnerability to cause a crash or possibly leak\nsensitive information. (CVE-2018-20721)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"uriparser","version":"0.8.4-1+deb9u2build0.18.04.1","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-doc","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"},{"name":"liburiparser-dev","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"},{"name":"liburiparser1","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19198","CVE-2018-19199","CVE-2018-20721","CVE-2018-19200"]},{"id":"USN-5172-2","title":"uriparser vulnerability","summary":"Several security issues were fixed in uriparser.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-09T11:45:04.355182","description":"USN-5172-1 fixed vulnerabilities in uriparser.\nThis update provides the corresponding updates for Ubuntu 14.04 ESM and\nUbuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that uriparser mishandled certain input. An attacker\n could use this vulnerability to cause uriparser to crash or possibly\n execute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)\n\n It was discovered that uriparser incorrectly handled certain URIs. An\n attacker could use this vulnerability to cause a crash or possibly leak\n sensitive information. (CVE-2018-20721)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"uriparser","version":"0.7.5-1ubuntu2+esm2","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-dev","version":"0.7.5-1ubuntu2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-infra"},{"name":"liburiparser1","version":"0.7.5-1ubuntu2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"uriparser","version":"0.8.4-1ubuntu0.16.04.1~esm2","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-doc","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"},{"name":"liburiparser-dev","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"},{"name":"liburiparser1","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-19199","CVE-2018-19200","CVE-2018-19198","CVE-2018-20721"]}]},{"id":"CVE-2018-19199","published":"2018-11-12T15:29:00","updated_at":"2025-08-25T22:51:29.928001+00:00","description":"\nAn issue was discovered in uriparser before 0.9.0. UriQuery.c allows an\ninteger overflow via a uriComposeQuery* or uriComposeQueryEx* function\nbecause of an unchecked multiplication.","ubuntu_description":"\nIt was discovered that uriparser mishandled certain input. An attacker could\nuse this vulnerability to cause uriparser to crash or possibly execute\narbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/uriparser/uriparser/commit/f76275d4a91b28d687250525d3a0c5509bbd666f","https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog","https://ubuntu.com/security/notices/USN-5172-1","https://www.cve.org/CVERecord?id=CVE-2018-19199","https://ubuntu.com/security/notices/USN-5172-2"],"bugs":[""],"patches":{"uriparser":[]},"tags":{},"packages":[{"name":"uriparser","source":"https://ubuntu.com/security/cve?package=uriparser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=uriparser","debian":"https://tracker.debian.org/pkg/uriparser","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.8.4-1+deb9u2build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.9.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.7.5-1ubuntu2+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"0.9.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.4-1ubuntu0.16.04.1~esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-5172-1","USN-5172-2"],"notices":[{"id":"USN-5172-1","title":"uriparser vulnerabilities","summary":"Several security issues were fixed in uriparser.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-06T12:53:01.218019","description":"It was discovered that uriparser mishandled certain input. An attacker\ncould use this vulnerability to cause uriparser to crash or possibly\nexecute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)\n\nIt was discovered that uriparser incorrectly handled certain URIs. An\nattacker could use this vulnerability to cause a crash or possibly leak\nsensitive information. (CVE-2018-20721)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"uriparser","version":"0.8.4-1+deb9u2build0.18.04.1","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-doc","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"},{"name":"liburiparser-dev","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"},{"name":"liburiparser1","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19198","CVE-2018-19199","CVE-2018-20721","CVE-2018-19200"]},{"id":"USN-5172-2","title":"uriparser vulnerability","summary":"Several security issues were fixed in uriparser.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-09T11:45:04.355182","description":"USN-5172-1 fixed vulnerabilities in uriparser.\nThis update provides the corresponding updates for Ubuntu 14.04 ESM and\nUbuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that uriparser mishandled certain input. An attacker\n could use this vulnerability to cause uriparser to crash or possibly\n execute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)\n\n It was discovered that uriparser incorrectly handled certain URIs. An\n attacker could use this vulnerability to cause a crash or possibly leak\n sensitive information. (CVE-2018-20721)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"uriparser","version":"0.7.5-1ubuntu2+esm2","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-dev","version":"0.7.5-1ubuntu2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-infra"},{"name":"liburiparser1","version":"0.7.5-1ubuntu2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"uriparser","version":"0.8.4-1ubuntu0.16.04.1~esm2","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-doc","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"},{"name":"liburiparser-dev","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"},{"name":"liburiparser1","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-19199","CVE-2018-19200","CVE-2018-19198","CVE-2018-20721"]}]},{"id":"CVE-2018-19198","published":"2018-11-12T15:29:00","updated_at":"2025-08-25T22:51:29.928001+00:00","description":"\nAn issue was discovered in uriparser before 0.9.0. UriQuery.c allows an\nout-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function\nbecause the '&' character is mishandled in certain contexts.","ubuntu_description":"\nIt was discovered that uriparser mishandled certain input. An attacker could\nuse this vulnerability to cause uriparser to crash or possibly execute\narbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/uriparser/uriparser/commit/864f5d4c127def386dd5cc926ad96934b297f04e","https://github.com/uriparser/uriparser/blob/uriparser-0.9.0/ChangeLog","https://ubuntu.com/security/notices/USN-5172-1","https://www.cve.org/CVERecord?id=CVE-2018-19198","https://ubuntu.com/security/notices/USN-5172-2"],"bugs":[""],"patches":{"uriparser":[]},"tags":{},"packages":[{"name":"uriparser","source":"https://ubuntu.com/security/cve?package=uriparser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=uriparser","debian":"https://tracker.debian.org/pkg/uriparser","statuses":[{"release_codename":"bionic","status":"released","description":"0.8.4-1+deb9u2build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.4-1ubuntu0.16.04.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.9.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.9.3-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.7.5-1ubuntu2+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"0.9.0-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5172-1","USN-5172-2"],"notices":[{"id":"USN-5172-1","title":"uriparser vulnerabilities","summary":"Several security issues were fixed in uriparser.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-06T12:53:01.218019","description":"It was discovered that uriparser mishandled certain input. An attacker\ncould use this vulnerability to cause uriparser to crash or possibly\nexecute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)\n\nIt was discovered that uriparser incorrectly handled certain URIs. An\nattacker could use this vulnerability to cause a crash or possibly leak\nsensitive information. (CVE-2018-20721)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"uriparser","version":"0.8.4-1+deb9u2build0.18.04.1","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-doc","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"},{"name":"liburiparser-dev","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"},{"name":"liburiparser1","version":"0.8.4-1+deb9u2build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":"https://launchpad.net/ubuntu/+source/uriparser/0.8.4-1+deb9u2build0.18.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19198","CVE-2018-19199","CVE-2018-20721","CVE-2018-19200"]},{"id":"USN-5172-2","title":"uriparser vulnerability","summary":"Several security issues were fixed in uriparser.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-12-09T11:45:04.355182","description":"USN-5172-1 fixed vulnerabilities in uriparser.\nThis update provides the corresponding updates for Ubuntu 14.04 ESM and\nUbuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that uriparser mishandled certain input. An attacker\n could use this vulnerability to cause uriparser to crash or possibly\n execute arbitrary code. (CVE-2018-19198, CVE-2018-19199, CVE-2018-19200)\n\n It was discovered that uriparser incorrectly handled certain URIs. An\n attacker could use this vulnerability to cause a crash or possibly leak\n sensitive information. (CVE-2018-20721)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"uriparser","version":"0.7.5-1ubuntu2+esm2","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-dev","version":"0.7.5-1ubuntu2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-infra"},{"name":"liburiparser1","version":"0.7.5-1ubuntu2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"uriparser","version":"0.8.4-1ubuntu0.16.04.1~esm2","description":"Strictly RFC 3986 compliant URI parsing library","is_source":true},{"name":"liburiparser-doc","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"},{"name":"liburiparser-dev","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"},{"name":"liburiparser1","version":"0.8.4-1ubuntu0.16.04.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/uriparser","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-19199","CVE-2018-19200","CVE-2018-19198","CVE-2018-20721"]}]},{"id":"CVE-2018-19210","published":"2018-11-12T00:00:00","updated_at":"2025-08-25T22:51:34.744515+00:00","description":"\nIn LibTIFF 4.0.9, there is a NULL pointer dereference in the\nTIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial\nof service attack, as demonstrated by tiffset.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3906-1","https://www.cve.org/CVERecord?id=CVE-2018-19210"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2820","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913675"],"patches":{"tiff":["other: https://gitlab.com/libtiff/libtiff/merge_requests/47","upstream: https://gitlab.com/libtiff/libtiff/commit/d0a842c5dbad2609aed43c701a12ed12461d3405","upstream: https://gitlab.com/libtiff/libtiff/commit/38ede78b13810ff0fa8e61f86ef9aa0ab2964668"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.0.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.0.9-6ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-3906-1"],"notices":[{"id":"USN-3906-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-03-12T13:08:54.152837","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"tiff","version":"4.0.9-5ubuntu0.2","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-dev","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-doc","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-tools","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff5","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiffxx5","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"}],"cosmic":[{"name":"tiff","version":"4.0.9-6ubuntu0.2","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-dev","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-doc","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-opengl","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-tools","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff5","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff5-dev","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiffxx5","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"}],"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.11","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10779","CVE-2018-12900","CVE-2018-17000","CVE-2018-19210","CVE-2019-6128","CVE-2019-7663"]}]},{"id":"CVE-2018-19143","published":"2018-11-11T05:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nOpen Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31,\nand 6.0.x before 6.0.13 allows an authenticated user to delete files via a\nmodified submission form because upload caching is mishandled.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://community.otrs.com/security-advisory-2018-07-security-update-for-otrs-framework/","https://www.cve.org/CVERecord?id=CVE-2018-19143"],"bugs":[""],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19142","published":"2018-11-11T05:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nOpen Ticket Request System (OTRS) 6.0.x before 6.0.13 allows an admin to\nconduct an XSS attack via a modified URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://community.otrs.com/security-advisory-2018-08-security-update-for-otrs-framework/","https://www.cve.org/CVERecord?id=CVE-2018-19142"],"bugs":[""],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"6.0.13-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19141","published":"2018-11-11T05:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nOpen Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before\n5.0.31 allows an admin to conduct an XSS attack via a modified URL because\nuser and customer preferences are mishandled.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://community.otrs.com/security-advisory-2018-09-security-update-for-otrs-framework/","https://www.cve.org/CVERecord?id=CVE-2018-19141"],"bugs":[""],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"6.0.5-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19149","published":"2018-11-10T00:00:00","updated_at":"2025-08-25T22:51:29.928001+00:00","description":"\nPoppler before 0.70.0 has a NULL pointer dereference in\n_poppler_attachment_new when called from\npoppler_annot_file_attachment_get_attachment.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3837-1","https://ubuntu.com/security/notices/USN-3837-2","https://www.cve.org/CVERecord?id=CVE-2018-19149"],"bugs":["https://gitlab.freedesktop.org/poppler/poppler/issues/664","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914600"],"patches":{"poppler":["upstream: https://github.com/freedesktop/poppler/commit/f162ecdea0dda5dbbdb45503c1d55d9afaa41d44"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"cosmic","status":"released","description":"0.68.0-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.13","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.9","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.62.0-2ubuntu2.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.70.0","component":null,"pocket":"security"}]}],"notices_ids":["USN-3837-2","USN-3837-1"],"notices":[{"id":"USN-3837-2","title":"poppler regression","summary":"USN-3837-1 introduced a regression in poppler.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-12-11T16:16:08.114982","description":"USN-3837-1 fixed vulnerabilities in poppler. A regression was reported\nregarding the previous update. This update fixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n It was discovered that poppler incorrectly handled certain PDF files.\n An attacker could possibly use this issue to cause a denial of service.\n (CVE-2018-16646)\n\n It was discovered that poppler incorrectly handled certain PDF files.\n An attacker could possibly use this issue to cause a denial of service.\n This issue only affected Ubuntu 16.04 LTS.\n (CVE-2018-19149)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.5","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.5","pocket":"security"}],"cosmic":[{"name":"poppler","version":"0.68.0-0ubuntu1.3","description":"PDF rendering library","is_source":true},{"name":"libpoppler79","version":"0.68.0-0ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.3"},{"name":"poppler-utils","version":"0.68.0-0ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.3"}],"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.14","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.14","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.10","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.10","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-16646","CVE-2018-19149"]},{"id":"USN-3837-1","title":"poppler vulnerabilities","summary":"Several security issues were fixed in poppler.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-12-04T11:47:21.130868","description":"It was discovered that poppler incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060)\n\nIt was discovered that poppler incorrectly handled certain PDF files.\nAn attacker could possibly use this issue to cause a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2018-19149)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.4","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.4","pocket":"security"}],"cosmic":[{"name":"poppler","version":"0.68.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"libpoppler79","version":"0.68.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.2"},{"name":"poppler-utils","version":"0.68.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.68.0-0ubuntu1.2"}],"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.13","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.13","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.9","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.9","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-16646","CVE-2018-19058","CVE-2018-19059","CVE-2018-19060","CVE-2018-19149"]}]},{"id":"CVE-2018-19139","published":"2018-11-09T21:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nAn issue has been found in JasPer 2.0.14. There is a memory leak in\njas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19139"],"bugs":["https://github.com/mdadams/jasper/issues/188"],"patches":{"jasper":["other: https://github.com/jasper-maint/jasper/pull/38"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was deferred [2020-07-22]","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-14644","published":"2018-11-09T19:29:00","updated_at":"2025-08-25T22:47:44.093585+00:00","description":"\nAn issue has been found in PowerDNS Recursor from 4.0.0 up to and including\n4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can\nlead to a zone being wrongly cached as failing DNSSEC validation. It only\narises if the parent zone is signed, and all the authoritative servers for\nthat parent zone answer with FORMERR to a query for at least one of the\nmeta-types. As a result, subsequent queries from clients requesting DNSSEC\nvalidation will be answered with a ServFail.","ubuntu_description":"","notes":[{"author":"hlibk","note":"pdns is not affected, but pdns-recursor is.\nDNSSEC processing is disabled on xenial."}],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2018-07.html","https://downloads.powerdns.com/patches/2018-07/","https://www.cve.org/CVERecord?id=CVE-2018-14644","https://ubuntu.com/security/notices/USN-7203-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=913162"],"patches":{"pdns":[],"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns","source":"https://ubuntu.com/security/cve?package=pdns","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pdns","debian":"https://tracker.debian.org/pkg/pdns","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"dnssec disabled","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.1.7-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.2.0-6","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.1.1-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"4.0.0~alpha2-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-7203-1"],"notices":[{"id":"USN-7203-1","title":"PowerDNS vulnerabilities","summary":"Several security issues were fixed in PowerDNS.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2025-01-14T13:40:35.011945","description":"Wei Hao discovered that PowerDNS Authoritative Server incorrectly handled\nmemory when accessing certain files. An attacker could possibly use this\nissue to achieve arbitrary code execution. (CVE-2018-1046)\n\nIt was discovered that PowerDNS Authoritative Server and PowerDNS Recursor\nincorrectly handled memory when receiving certain remote input. An attacker\ncould possibly use this issue to cause denial of service. (CVE-2018-10851)\n\nKees Monshouwer discovered that PowerDNS Authoritative Server and PowerDNS\nRecursor incorrectly handled request validation after having cached\nmalformed input. An attacker could possibly use this issue to cause denial\nof service. (CVE-2018-14626)\n\nToshifumi Sakaguchi discovered that PowerDNS Recursor incorrectly handled\nrequests after having cached malformed input. An attacker could possibly\nuse this issue to cause denial of service. (CVE-2018-14644)\n\nNathaniel Ferguson discovered that PowerDNS Authoritative Server\nincorrectly handled memory when receiving certain remote input. An attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2020-17482)\n\nNicolas Dehaine and Dmitry Shabanov discovered that PowerDNS Authoritative\nServer and PowerDNS Recursor incorrectly handled IXFR requests in certain\ncircumstances. An attacker could possibly use this issue to cause denial of\nservice. (CVE-2022-27227)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"pdns","version":"4.1.1-1ubuntu0.1~esm1","description":"extremely powerful and versatile nameserver","is_source":true},{"name":"pdns-recursor","version":"4.1.1-2ubuntu0.1~esm1","description":"PowerDNS Recursor","is_source":true},{"name":"pdns-backend-bind","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-geoip","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-ldap","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-lua","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mydns","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mysql","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-odbc","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-opendbx","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pgsql","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pipe","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-remote","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-sqlite3","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-tinydns","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-recursor","version":"4.1.1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns-recursor","version_link":null,"pocket":"esm-apps"},{"name":"pdns-server","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-tools","version":"4.1.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"pdns","version":"4.2.1-1ubuntu0.1~esm1","description":"extremely powerful and versatile nameserver","is_source":true},{"name":"pdns-recursor","version":"4.2.1-1ubuntu0.1~esm1","description":"PowerDNS Recursor","is_source":true},{"name":"pdns-backend-bind","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-geoip","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-ldap","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-lua","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mydns","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mysql","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-odbc","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pgsql","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pipe","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-remote","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-sqlite3","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-tinydns","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-ixfrdist","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-recursor","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns-recursor","version_link":null,"pocket":"esm-apps"},{"name":"pdns-server","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-tools","version":"4.2.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"pdns","version":"4.5.3-1ubuntu0.1~esm1","description":"extremely powerful and versatile nameserver","is_source":true},{"name":"pdns-recursor","version":"4.6.0-1ubuntu1+esm1","description":"PowerDNS Recursor","is_source":true},{"name":"pdns-backend-bind","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-geoip","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-ldap","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-lmdb","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-lua2","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mysql","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-odbc","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pgsql","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pipe","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-remote","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-sqlite3","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-tinydns","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-ixfrdist","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-recursor","version":"4.6.0-1ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns-recursor","version_link":null,"pocket":"esm-apps"},{"name":"pdns-server","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-tools","version":"4.5.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"pdns","version":"4.0.0~alpha2-3ubuntu0.1~esm1","description":"extremely powerful and versatile nameserver","is_source":true},{"name":"pdns-recursor","version":"4.0.0~alpha2-2ubuntu0.1+esm1","description":"PowerDNS Recursor","is_source":true},{"name":"pdns-backend-geoip","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-ldap","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-lua","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mydns","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-mysql","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pgsql","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-pipe","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-remote","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-sqlite3","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-backend-tinydns","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-recursor","version":"4.0.0~alpha2-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns-recursor","version_link":null,"pocket":"esm-apps"},{"name":"pdns-server","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"},{"name":"pdns-tools","version":"4.0.0~alpha2-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pdns","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-1046","CVE-2018-10851","CVE-2020-17482","CVE-2018-14626","CVE-2022-27227","CVE-2018-14644"]}]},{"id":"CVE-2018-19131","published":"2018-11-09T11:29:00","updated_at":"2025-08-25T22:51:29.928001+00:00","description":"\nSquid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S)\nerror page generation for certificate errors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"squid in Ubuntu is not built with OpenSSL support, so Ubuntu\nisn't actually vulnerable to this issue."}],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.squid-cache.org/Advisories/SQUID-2018_4.txt","http://www.squid-cache.org/Versions/v5/changesets/squid-5-6feeb15ff312f3e145763adf8d234ed6a0b3f11d.patch","https://github.com/squid-cache/squid/pull/306","https://www.cve.org/CVERecord?id=CVE-2018-19131"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=912293"],"patches":{"squid3":[],"squid":[]},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"not built with --with-openssl","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"bionic","status":"not-affected","description":"not built with --with-openssl","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"not built with --with-openssl","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [not built with --with-openssl]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19130","published":"2018-11-09T11:29:00","updated_at":"2025-08-04T19:27:34.070613+00:00","description":"\nIn Libav 12.3, there is an invalid memory access in vc1_decode_frame in\nlibavcodec/vc1dec.c that allows attackers to cause a denial-of-service via\na crafted aac file. NOTE: This may be a duplicate of CVE-2017-17127","ubuntu_description":"","notes":[{"author":"ebarretto","note":"No fix available as of 2019-03-01"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.libav.org/show_bug.cgi?id=1139","https://www.cve.org/CVERecord?id=CVE-2018-19130"],"bugs":[""],"patches":{"libav":[]},"tags":{},"packages":[{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19129","published":"2018-11-09T11:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nIn Libav 12.3, a NULL pointer dereference (RIP points to zero) issue in\nff_mpa_synth_filter_float in libavcodec/mpegaudiodsp_template.c can cause a\nsegmentation fault (application crash) via a crafted mov file.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"No fix available as of 2019-03-01"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.libav.org/show_bug.cgi?id=1138","https://www.cve.org/CVERecord?id=CVE-2018-19129"],"bugs":[""],"patches":{"libav":[]},"tags":{},"packages":[{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19128","published":"2018-11-09T11:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nIn Libav 12.3, there is a heap-based buffer over-read in decode_frame in\nlibavcodec/lcldec.c that allows an attacker to cause denial-of-service via\na crafted avi file.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"No fix available as of 2019-03-01"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.libav.org/show_bug.cgi?id=1137","https://www.cve.org/CVERecord?id=CVE-2018-19128"],"bugs":[""],"patches":{"libav":[]},"tags":{},"packages":[{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19132","published":"2018-11-09T00:00:00","updated_at":"2025-08-25T22:51:29.928001+00:00","description":"\nSquid before 4.4, when SNMP is enabled, allows a denial of service (Memory\nLeak) via an SNMP packet.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"snmp port is disabled by default in Ubuntu"}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.squid-cache.org/Advisories/SQUID-2018_5.txt","https://ubuntu.com/security/notices/USN-4059-1","https://www.cve.org/CVERecord?id=CVE-2018-19132"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=912294"],"patches":{"squid3":["upstream: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-bc9786119f058a76ddf0625424bc33d36460b9a2.patch"],"squid":["upstream: http://www.squid-cache.org/Versions/v4/changesets/squid-4-983c5c36e5f109512ed1af38a329d0b5d0967498.patch"]},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.4-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"bionic","status":"released","description":"3.5.27-1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.12-1ubuntu7.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-4059-1"],"notices":[{"id":"USN-4059-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-07-15T14:38:10.385320","description":"It was discovered that Squid incorrectly handled certain SNMP packets. A\nremote attacker could possibly use this issue to cause memory consumption,\nleading to a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 18.04 LTS. (CVE-2018-19132)\n\nIt was discovered that Squid incorrectly handled the cachemgr.cgi web\nmodule. A remote attacker could possibly use this issue to conduct\ncross-site scripting (XSS) attacks. (CVE-2019-13345)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"squid3","version":"3.5.27-1ubuntu1.2","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.27-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.2","pocket":"security"},{"name":"squid-cgi","version":"3.5.27-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.2","pocket":"security"},{"name":"squid-common","version":"3.5.27-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.2","pocket":"security"},{"name":"squid-purge","version":"3.5.27-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.2","pocket":"security"},{"name":"squid3","version":"3.5.27-1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.2","pocket":"security"},{"name":"squidclient","version":"3.5.27-1ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.2","pocket":"security"}],"disco":[{"name":"squid","version":"4.4-1ubuntu2.1","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"4.4-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.4-1ubuntu2.1"},{"name":"squid-cgi","version":"4.4-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.4-1ubuntu2.1"},{"name":"squid-common","version":"4.4-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.4-1ubuntu2.1"},{"name":"squid-purge","version":"4.4-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.4-1ubuntu2.1"},{"name":"squid3","version":"4.4-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.4-1ubuntu2.1"},{"name":"squidclient","version":"4.4-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.4-1ubuntu2.1"}],"xenial":[{"name":"squid3","version":"3.5.12-1ubuntu7.7","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"3.5.12-1ubuntu7.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.7","pocket":"security"},{"name":"squid-cgi","version":"3.5.12-1ubuntu7.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.7","pocket":"security"},{"name":"squid-common","version":"3.5.12-1ubuntu7.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.7","pocket":"security"},{"name":"squid-purge","version":"3.5.12-1ubuntu7.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.7","pocket":"security"},{"name":"squid3","version":"3.5.12-1ubuntu7.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.7","pocket":"security"},{"name":"squidclient","version":"3.5.12-1ubuntu7.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid3","version_link":"https://launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19132","CVE-2019-13345"]}]},{"id":"CVE-2018-19046","published":"2018-11-08T20:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nkeepalived 2.0.8 didn't check for existing plain files when writing data to\na temporary file upon a call to PrintData or PrintStats. If a local\nattacker had previously created a file with the expected name (e.g.,\n/tmp/keepalived.data or /tmp/keepalived.stats), with read access for the\nattacker and write access for the keepalived process, then this potentially\nleaked sensitive information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"xenial and earlier don't have dbus support"}],"codename":null,"priority":"low","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19046"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1015141","https://github.com/acassen/keepalived/issues/1048"],"patches":{"keepalived":["upstream: https://github.com/acassen/keepalived/commit/ac8e2ef053de273ce7a0cf0cb611e599dca4b298","upstream: https://github.com/acassen/keepalived/commit/26c8d6374db33bcfcdcd758b1282f12ceef4b94f","upstream: https://github.com/acassen/keepalived/commit/17f944144b3d9c5131569b1cc988cc90fd676671"]},"tags":{},"packages":[{"name":"keepalived","source":"https://ubuntu.com/security/cve?package=keepalived","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=keepalived","debian":"https://tracker.debian.org/pkg/keepalived","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19045","published":"2018-11-08T20:29:00","updated_at":"2025-08-26T12:06:35.871397+00:00","description":"\nkeepalived 2.0.8 used mode 0666 when creating new temporary files upon a\ncall to PrintData or PrintStats, potentially leaking sensitive information.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"xenial and earlier don't have dbus support"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19045"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1015141","https://github.com/acassen/keepalived/issues/1048"],"patches":{"keepalived":["upstream: https://github.com/acassen/keepalived/commit/c6247a9ef2c7b33244ab1d3aa5d629ec49f0a067","upstream: https://github.com/acassen/keepalived/commit/5241e4d7b177d0b6f073cfc9ed5444bf51ec89d6"]},"tags":{},"packages":[{"name":"keepalived","source":"https://ubuntu.com/security/cve?package=keepalived","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=keepalived","debian":"https://tracker.debian.org/pkg/keepalived","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19044","published":"2018-11-08T20:29:00","updated_at":"2026-05-21T12:54:01.485107+00:00","description":"\nkeepalived 2.0.8 didn't check for pathnames with symlinks when writing data\nto a temporary file upon a call to PrintData or PrintStats. This allowed\nlocal users to overwrite arbitrary files if fs.protected_symlinks is set to\n0, as demonstrated by a symlink from /tmp/keepalived.data or\n/tmp/keepalived.stats to /etc/passwd.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"xenial and earlier don't have dbus support"}],"codename":null,"priority":"low","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-19044"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1015141","https://github.com/acassen/keepalived/issues/1048"],"patches":{"keepalived":["upstream: https://github.com/acassen/keepalived/commit/04f2d32871bb3b11d7dc024039952f2fe2750306"]},"tags":{"keepalived":["symlink-restriction","hardlink-restriction"]},"packages":[{"name":"keepalived","source":"https://ubuntu.com/security/cve?package=keepalived","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=keepalived","debian":"https://tracker.debian.org/pkg/keepalived","statuses":[{"release_codename":"kinetic","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.0.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-19105","published":"2018-11-08T08:29:00","updated_at":"2025-08-25T22:51:25.173788+00:00","description":"\nLibreCAD 2.1.3 allows remote attackers to cause a denial of service\n(0x89C04589 write access violation and application crash) or possibly have\nunspecified other impact via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://code610.blogspot.com/2018/11/crashing-librecad-213.html","https://ubuntu.com/security/notices/USN-5957-1","https://www.cve.org/CVERecord?id=CVE-2018-19105"],"bugs":[""],"patches":{"librecad":[]},"tags":{},"packages":[{"name":"librecad","source":"https://ubuntu.com/security/cve?package=librecad","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=librecad","debian":"https://tracker.debian.org/pkg/librecad","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.1.2-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.3-1.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.0.9-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"2.1.3-1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-5957-1"],"notices":[{"id":"USN-5957-1","title":"LibreCAD vulnerabilities","summary":"Several security issues were fixed in LibreCAD.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-15T16:20:03.636286","description":"Cody Sixteen discovered that LibreCAD incorrectly\nhandled memory when parsing DXF files. An attacker could\nuse this issue to cause LibreCAD to crash, leading to a\ndenial of service. This issue only affected\nUbuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)\n\nLilith of Cisco Talos discovered that LibreCAD incorrectly\nhandled memory when parsing DWG files. An attacker could\nuse this issue to cause LibreCAD to crash, leading to a\ndenial of service, or possibly execute arbitrary code.\n(CVE-2021-21898, CVE-2021-21899)\n\nLilith of Cisco Talos discovered that LibreCAD incorrectly\nhandled memory when parsing DRW files. An attacker could\nuse this issue to cause LibreCAD to crash, leading to a\ndenial of service, or possibly execute arbitrary code.\n(CVE-2021-21900)\n\nAlbin Eldstål-Ahrens discovered that LibreCAD incorrectly\nhandled memory when parsing JWW files. An attacker could\nuse this issue to cause LibreCAD to crash, leading to a\ndenial of service, or possibly execute arbitrary code.\n(CVE-2021-45341, CVE-2021-45342)\n\nAlbin Eldstål-Ahrens discovered that LibreCAD incorrectly\nhandled memory when parsing DXF files. An attacker could\nuse this issue to cause LibreCAD to crash, leading to a\ndenial of service. (CVE-2021-45343)\n","is_hidden":false,"release_packages":{"focal":[{"name":"librecad","version":"2.1.3-1.2+deb10u1build0.20.04.1","description":"Computer-aided design (CAD) system","is_source":true},{"name":"librecad-data","version":"2.1.3-1.2+deb10u1build0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librecad","version_link":"https://launchpad.net/ubuntu/+source/librecad/2.1.3-1.2+deb10u1build0.20.04.1","pocket":"security"},{"name":"librecad","version":"2.1.3-1.2+deb10u1build0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librecad","version_link":"https://launchpad.net/ubuntu/+source/librecad/2.1.3-1.2+deb10u1build0.20.04.1","pocket":"security"}],"bionic":[{"name":"librecad","version":"2.1.2-1ubuntu0.1~esm1","description":"Computer-aided design (CAD) system","is_source":true},{"name":"librecad-data","version":"2.1.2-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librecad","version_link":null,"pocket":"esm-apps"},{"name":"librecad","version":"2.1.2-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librecad","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"librecad","version":"2.0.9-2ubuntu0.1~esm1","description":"Computer-aided design (CAD) system","is_source":true},{"name":"librecad-data","version":"2.0.9-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/librecad","version_link":null,"pocket":"esm-apps"},{"name":"librecad","version":"2.0.9-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/librecad","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-21899","CVE-2021-21898","CVE-2021-45341","CVE-2018-19105","CVE-2021-21900","CVE-2021-45342","CVE-2021-45343"]}]},{"id":"CVE-2018-19115","published":"2018-11-08T00:00:00","updated_at":"2025-08-25T22:51:29.928001+00:00","description":"\nkeepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP\nstatus codes resulting in DoS or possibly unspecified other impact, because\nextract_status_code in lib/html.c has no validation of the status code and\ninstead writes an unlimited amount of data to the heap.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/acassen/keepalived/pull/961","https://ubuntu.com/security/notices/USN-3995-1","https://ubuntu.com/security/notices/USN-3995-2","https://www.cve.org/CVERecord?id=CVE-2018-19115"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1015141","https://github.com/acassen/keepalived/issues/960","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=914393"],"patches":{"keepalived":["upstream: https://github.com/acassen/keepalived/commit/f28015671a4b04785859d1b4b1327b367b6a10e9"]},"tags":{},"packages":[{"name":"keepalived","source":"https://ubuntu.com/security/cve?package=keepalived","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=keepalived","debian":"https://tracker.debian.org/pkg/keepalived","statuses":[{"release_codename":"bionic","status":"released","description":"1:1.3.9-1ubuntu0.18.04.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:1.3.9-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.0.10-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.2.7-1ubuntu1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"2.0.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.2.24-1ubuntu0.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3995-1","USN-3995-2"],"notices":[{"id":"USN-3995-1","title":"Keepalived vulnerability","summary":"Keepalived could be made to crash or run programs if it received\nspecially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-05-28T12:38:48.054574","description":"It was discovered that Keepalived incorrectly handled certain HTTP status\nresponse codes. A remote attacker could use this issue to cause Keepalived\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"keepalived","version":"1:1.3.9-1ubuntu0.18.04.2","description":"Failover and monitoring daemon for LVS clusters","is_source":true},{"name":"keepalived","version":"1:1.3.9-1ubuntu0.18.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/keepalived","version_link":"https://launchpad.net/ubuntu/+source/keepalived/1:1.3.9-1ubuntu0.18.04.2","pocket":"security"}],"cosmic":[{"name":"keepalived","version":"1:1.3.9-1ubuntu1.1","description":"Failover and monitoring daemon for LVS clusters","is_source":true},{"name":"keepalived","version":"1:1.3.9-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/keepalived","version_link":"https://launchpad.net/ubuntu/+source/keepalived/1:1.3.9-1ubuntu1.1"}],"xenial":[{"name":"keepalived","version":"1:1.2.24-1ubuntu0.16.04.2","description":"Failover and monitoring daemon for LVS clusters","is_source":true},{"name":"keepalived","version":"1:1.2.24-1ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/keepalived","version_link":"https://launchpad.net/ubuntu/+source/keepalived/1:1.2.24-1ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-19115"]},{"id":"USN-3995-2","title":"Keepalived vulnerability","summary":"Keepalived could be made to crash or run programs if it received\nspecially crafted network traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-05-28T17:02:21.711356","description":"USN-3995-1 fixed a vulnerability in keepalived. This update provides\nthe corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Keepalived incorrectly handled certain HTTP status\n response codes. A remote attacker could use this issue to cause Keepalived\n to crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"keepalived","version":"1:1.2.2-3ubuntu1.2","description":"Failover and monitoring daemon for LVS clusters","is_source":true},{"name":"keepalived","version":"1:1.2.2-3ubuntu1.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/keepalived","version_link":"https://launchpad.net/ubuntu/+source/keepalived/1:1.2.2-3ubuntu1.2"}],"trusty":[{"name":"keepalived","version":"1:1.2.7-1ubuntu1+esm1","description":"Failover and monitoring daemon for LVS clusters","is_source":true},{"name":"keepalived","version":"1:1.2.7-1ubuntu1+esm1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/keepalived","version_link":"https://launchpad.net/ubuntu/+source/keepalived/1:1.2.7-1ubuntu1+esm1"}]},"type":"USN","cves_ids":["CVE-2018-19115"]}]}],"offset":51260,"limit":20,"total_results":79316}