{"cves":[{"id":"CVE-2018-10777","published":"2018-05-07T07:29:00","updated_at":"2025-07-17T16:43:02.591232+00:00","description":"\nBuffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain\nthrough 1.5.2-r2 allows remote attackers to cause a denial of service\n(application crash) or possibly have unspecified other impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://docs.google.com/document/d/11Ms9j82hpH8iA0oc4QH0qUG6gq-ZOiqI0YroAFMrcD8/edit","https://www.cve.org/CVERecord?id=CVE-2018-10777"],"bugs":[""],"patches":{"mp3gain":[]},"tags":{},"packages":[{"name":"mp3gain","source":"https://ubuntu.com/security/cve?package=mp3gain","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mp3gain","debian":"https://tracker.debian.org/pkg/mp3gain","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10776","published":"2018-05-07T07:29:00","updated_at":"2025-07-17T16:43:02.591232+00:00","description":"\nThe getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2\nallows remote attackers to cause a denial of service (segmentation fault\nand application crash) or possibly have unspecified other impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://docs.google.com/document/d/1gkHfRWO9f-FTBhZ3ZT3RMZZ_JbJ18ZIkH2GlVTV35cQ/edit","https://www.cve.org/CVERecord?id=CVE-2018-10776"],"bugs":[""],"patches":{"mp3gain":[]},"tags":{},"packages":[{"name":"mp3gain","source":"https://ubuntu.com/security/cve?package=mp3gain","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mp3gain","debian":"https://tracker.debian.org/pkg/mp3gain","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10775","published":"2018-05-07T07:29:00","updated_at":"2025-07-11T07:39:20.663270+00:00","description":"\nNULL pointer dereference in the _fields_add function in fields.c in\nlibbibcore.a in bibutils through 6.2 allows remote attackers to cause a\ndenial of service (application crash), as demonstrated by end2xml.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://drive.google.com/drive/u/1/folders/1qtq272m7jJaEUPGFLvyXmIl5zNJv7rd1","https://www.cve.org/CVERecord?id=CVE-2018-10775"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898135"],"patches":{"bibutils":[]},"tags":{},"packages":[{"name":"bibutils","source":"https://ubuntu.com/security/cve?package=bibutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bibutils","debian":"https://tracker.debian.org/pkg/bibutils","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10774","published":"2018-05-07T07:29:00","updated_at":"2025-07-11T07:39:20.663270+00:00","description":"\nRead access violation in the isiin_keyword function in isiin.c in\nlibbibutils.a in bibutils through 6.2 allows remote attackers to cause a\ndenial of service (application crash), as demonstrated by isi2xml.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://docs.google.com/document/d/1BuCxbXaGL_3DyaWF8sGnMAWolmYQneRrxHt4mNPkBE4/edit","https://www.cve.org/CVERecord?id=CVE-2018-10774"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898135"],"patches":{"bibutils":[]},"tags":{},"packages":[{"name":"bibutils","source":"https://ubuntu.com/security/cve?package=bibutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bibutils","debian":"https://tracker.debian.org/pkg/bibutils","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10773","published":"2018-05-07T07:29:00","updated_at":"2025-07-11T07:39:20.663270+00:00","description":"\nNULL pointer deference in the addsn function in serialno.c in libbibcore.a\nin bibutils through 6.2 allows remote attackers to cause a denial of\nservice (application crash), as demonstrated by copac2xml.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://docs.google.com/document/d/1k598A16gV9HPwFXnYkyrPwoRbnbFX6LAMRyzb_dxLCM/edit","https://www.cve.org/CVERecord?id=CVE-2018-10773"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898135"],"patches":{"bibutils":[]},"tags":{},"packages":[{"name":"bibutils","source":"https://ubuntu.com/security/cve?package=bibutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bibutils","debian":"https://tracker.debian.org/pkg/bibutils","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10772","published":"2018-05-07T02:29:00","updated_at":"2025-08-25T22:43:45.573864+00:00","description":"\nThe tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows\nremote attackers to cause a denial of service (application crash) or\npossibly have unspecified other impact via a crafted file.","ubuntu_description":"","notes":[{"author":"debian","note":"Vulnerable code introduced after 0.25"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-10772"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1566260"],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10771","published":"2018-05-07T02:29:00","updated_at":"2025-08-25T22:43:40.892185+00:00","description":"\nStack-based buffer overflow in the get_key function in parse.c in abcm2ps\nthrough 8.13.20 allows remote attackers to cause a denial of service\n(application crash) or possibly have unspecified other impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/leesavide/abcm2ps/issues/17","https://github.com/leesavide/abcm2ps/commit/dc0372993674d0b50fedfbf7b9fad1239b8efc5f","https://drive.google.com/open?id=1HE9cht7WJPauA66acyJrEywXX8R4Hg-2","https://ubuntu.com/security/notices/USN-5961-1","https://www.cve.org/CVERecord?id=CVE-2018-10771"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898130"],"patches":{"abcm2ps":[]},"tags":{},"packages":[{"name":"abcm2ps","source":"https://ubuntu.com/security/cve?package=abcm2ps","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=abcm2ps","debian":"https://tracker.debian.org/pkg/abcm2ps","statuses":[{"release_codename":"xenial","status":"released","description":"7.8.9-1ubuntu0.16.04.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"7.8.9-1+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-5961-1"],"notices":[{"id":"USN-5961-1","title":"abcm2ps vulnerabilities","summary":"Several security issues were fixed in abcm2ps.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-16T14:18:37.293881","description":"It was discovered that abcm2ps incorrectly\nhandled memory when parsing specially crafted ABC files.\nAn attacker could use this issue to cause abcm2ps to crash,\nleading to a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 ESM\nand Ubuntu 18.04 LTS. \n(CVE-2018-10753, CVE-2018-10771, CVE-2019-1010069)\n\nChiba of Topsec Alpha Lab discovered that abcm2ps incorrectly\nhandled memory when parsing specially crafted ABC files.\nAn attacker could use this issue to cause abcm2ps to crash,\nleading to a denial of service.\n(CVE-2021-32434, CVE-2021-32435, CVE-2021-32436)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"abcm2ps","version":"8.14.11-0.1ubuntu0.1~esm1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"8.14.11-0.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"abcm2ps","version":"7.8.9-1+deb9u1build0.18.04.1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"7.8.9-1+deb9u1build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":"https://launchpad.net/ubuntu/+source/abcm2ps/7.8.9-1+deb9u1build0.18.04.1","pocket":"security"}],"focal":[{"name":"abcm2ps","version":"8.14.6-0.1ubuntu0.1~esm1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"8.14.6-0.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"abcm2ps","version":"7.8.9-1ubuntu0.16.04.1~esm1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"7.8.9-1ubuntu0.16.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-32435","CVE-2018-10771","CVE-2019-1010069","CVE-2021-32434","CVE-2021-32436","CVE-2018-10753"]}]},{"id":"CVE-2018-4200","published":"2018-05-07T00:00:00","updated_at":"2025-08-25T22:54:45.147730+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 11.3.1 is\naffected. Safari before 11.1 is affected. iCloud before 7.5 on Windows is\naffected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is\naffected. The issue involves the \"WebKit\" component. It allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site that triggers a\nWebCore::jsElementScrollHeightGetter use-after-free.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0004.html","https://ubuntu.com/security/notices/USN-3640-1","https://www.cve.org/CVERecord?id=CVE-2018-4200"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"2.20.2-0ubuntu0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.20.2-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.20.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.20.2-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.20.2-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3640-1"],"notices":[{"id":"USN-3640-1","title":"WebKitGTK+ vulnerability","summary":"A security issue was fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-05-08T14:30:14.045130","description":"Ivan Fratric discovered that WebKitGTK+ incorrectly handled certain web\ncontent. If a user were tricked into viewing a malicious website, a remote\nattacker could possibly exploit this to execute arbitrary code.\n","is_hidden":false,"release_packages":{"artful":[{"name":"webkit2gtk","version":"2.20.2-0ubuntu0.17.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.20.2-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.17.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.20.2-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.17.10.1"}],"bionic":[{"name":"webkit2gtk","version":"2.20.2-0ubuntu0.18.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.20.2-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.18.04.1","pocket":"security"}],"xenial":[{"name":"webkit2gtk","version":"2.20.2-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.20.2-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.20.2-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-4200"]}]},{"id":"CVE-2018-10779","published":"2018-05-07T00:00:00","updated_at":"2025-08-25T22:43:45.573864+00:00","description":"\nTIFFWriteScanline in tif_write.c in LibTIFF 3.8.2 has a heap-based buffer\nover-read, as demonstrated by bmp2tiff.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream removed the bmp2tiff utility in 4.0.7, but this issue\nis in the library, not the utility"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3906-1","https://ubuntu.com/security/notices/USN-3906-2","https://www.cve.org/CVERecord?id=CVE-2018-10779"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2788"],"patches":{"tiff":["upstream: https://gitlab.com/libtiff/libtiff/commit/981e43ecae83935625c86c9118c0778c942c7048"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.0.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.0.9-6ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-3906-2","USN-3906-1"],"notices":[{"id":"USN-3906-2","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-03-18T13:57:47.692667","description":"USN-3906-1 and USN-3864-1 fixed several vulnerabilities in LibTIFF. This update\nprovides the corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that LibTIFF incorrectly handled certain malformed\n images. If a user or automated system were tricked into opening a specially\n crafted image, a remote attacker could crash the application, leading to a\n denial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"precise":[{"name":"tiff","version":"3.9.5-2ubuntu1.12","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff4","version":"3.9.5-2ubuntu1.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.12"},{"name":"libtiff-tools","version":"3.9.5-2ubuntu1.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.12"}]},"type":"USN","cves_ids":["CVE-2018-10779","CVE-2018-12900","CVE-2018-17100","CVE-2018-17101","CVE-2018-18557","CVE-2019-6128","CVE-2019-7663"]},{"id":"USN-3906-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-03-12T13:08:54.152837","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"tiff","version":"4.0.9-5ubuntu0.2","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-dev","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-doc","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-tools","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff5","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiffxx5","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"}],"cosmic":[{"name":"tiff","version":"4.0.9-6ubuntu0.2","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-dev","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-doc","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-opengl","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-tools","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff5","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff5-dev","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiffxx5","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"}],"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.11","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10779","CVE-2018-12900","CVE-2018-17000","CVE-2018-19210","CVE-2019-6128","CVE-2019-7663"]}]},{"id":"CVE-2018-10767","published":"2018-05-06T23:29:00","updated_at":"2025-08-26T12:03:25.267638+00:00","description":"\nThere is a stack-based buffer over-read in calling GLib in the function\ngxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0\nbecause it does not reject negative return values from a\ng_input_stream_read call. A crafted input will lead to a remote denial of\nservice attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-10767"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898133","https://bugzilla.redhat.com/show_bug.cgi?id=1575188"],"patches":{"libgxps":[]},"tags":{},"packages":[{"name":"libgxps","source":"https://ubuntu.com/security/cve?package=libgxps","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgxps","debian":"https://tracker.debian.org/pkg/libgxps","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.3.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.3.2-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.3.2-4build3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.3.2-4build3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.3.2-4build3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.3.2-4build3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.3.2-4build3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10768","published":"2018-05-06T00:00:00","updated_at":"2025-08-25T22:43:40.892185+00:00","description":"\nThere is a NULL pointer dereference in the AnnotPath::getCoordsLength\nfunction in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted\ninput will lead to a remote denial of service attack. Later Ubuntu packages\nsuch as for Poppler 0.41.0 are not affected.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.freedesktop.org/show_bug.cgi?id=106408","https://ubuntu.com/security/notices/USN-3647-1","https://www.cve.org/CVERecord?id=CVE-2018-10768"],"bugs":[""],"patches":{"poppler":[]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3647-1"],"notices":[{"id":"USN-3647-1","title":"poppler vulnerabilities","summary":"poppler could be made to crash if it opened a specially crafted PDF.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-05-15T16:26:10.741296","description":"It was discovered that poppler incorrectly handled certain PDF files.\nAn attacker could possibly use this to cause a denial of service.\n(CVE-2017-18267)\n\nIt was discovered that poppler incorrectly handled certain PDF files.\nAn attacker could possibly use this to cause a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2018-10768)\n","is_hidden":false,"release_packages":{"artful":[{"name":"poppler","version":"0.57.0-2ubuntu4.3","description":"PDF rendering library","is_source":true},{"name":"libpoppler68","version":"0.57.0-2ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.57.0-2ubuntu4.3"},{"name":"poppler-utils","version":"0.57.0-2ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.57.0-2ubuntu4.3"}],"bionic":[{"name":"poppler","version":"0.62.0-2ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-cpp0v5","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-dev","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-glib8","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"libpoppler73","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"},{"name":"poppler-utils","version":"0.62.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.1","pocket":"security"}],"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.11","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.11","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.7","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-18267","CVE-2018-10768"]}]},{"id":"CVE-2018-0494","published":"2018-05-06T00:00:00","updated_at":"2025-08-25T22:42:23.942791+00:00","description":"\nGNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the\nresp_new function in http.c via a \\r\\n sequence in a continuation line.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/bug-wget/2018-05/msg00020.html","https://sintonen.fi/advisories/gnu-wget-cookie-injection.txt","https://ubuntu.com/security/notices/USN-3643-1","https://ubuntu.com/security/notices/USN-3643-2","https://www.cve.org/CVERecord?id=CVE-2018-0494"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898076","https://savannah.gnu.org/bugs/?53763"],"patches":{"wget":["other: https://git.savannah.gnu.org/cgit/wget.git/commit/?id=1fc9c95ec144499e69dc8ec76dbe07799d7d82cd"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"artful","status":"released","description":"1.19.1-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.19.4-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.15-1ubuntu1.14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.19.5-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.17.1-1ubuntu1.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3643-2","USN-3643-1"],"notices":[{"id":"USN-3643-2","title":"Wget vulnerability","summary":"Wget could be made to inject arbitrary cookie values.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-05-09T15:13:35.592286","description":"USN-3643-1 fixed a vulnerability in Wget. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Wget incorrectly handled certain inputs.\n An attacker could possibly use this to inject arbitrary cookie values.\n","is_hidden":false,"release_packages":{"precise":[{"name":"wget","version":"1.13.4-2ubuntu1.6","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.13.4-2ubuntu1.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.13.4-2ubuntu1.6"}]},"type":"USN","cves_ids":["CVE-2018-0494"]},{"id":"USN-3643-1","title":"Wget vulnerability","summary":"Wget could be made to inject arbitrary cookie values.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-05-09T13:11:27.932285","description":"It was discovered that Wget incorrectly handled certain inputs.\nAn attacker could possibly use this to inject arbitrary cookie values.\n","is_hidden":false,"release_packages":{"artful":[{"name":"wget","version":"1.19.1-3ubuntu1.2","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.1-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.19.1-3ubuntu1.2"}],"bionic":[{"name":"wget","version":"1.19.4-1ubuntu2.1","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.19.4-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.19.4-1ubuntu2.1","pocket":"security"},{"name":"wget-udeb","version":"1.19.4-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.19.4-1ubuntu2.1","pocket":"security"}],"trusty":[{"name":"wget","version":"1.15-1ubuntu1.14.04.4","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.15-1ubuntu1.14.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.15-1ubuntu1.14.04.4","pocket":"security"},{"name":"wget-udeb","version":"1.15-1ubuntu1.14.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.15-1ubuntu1.14.04.4","pocket":"security"}],"xenial":[{"name":"wget","version":"1.17.1-1ubuntu1.4","description":"retrieves files from the web","is_source":true},{"name":"wget","version":"1.17.1-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.17.1-1ubuntu1.4","pocket":"security"},{"name":"wget-udeb","version":"1.17.1-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.17.1-1ubuntu1.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-0494"]}]},{"id":"CVE-2018-10754","published":"2018-05-05T02:29:00","updated_at":"2025-08-04T19:27:26.665773+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none.\nReason: This candidate was withdrawn by its CNA. Further investigation\nshowed that it was not a security issue. Notes: none","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1566575","https://invisible-island.net/ncurses/NEWS.html#t20180414","https://drive.google.com/drive/u/2/folders/1klyBjovfKXhLqBhbWX1n9dwqD-qne5f2","https://www.cve.org/CVERecord?id=CVE-2018-10754"],"bugs":[""],"patches":{"ncurses":[]},"tags":{},"packages":[{"name":"ncurses","source":"https://ubuntu.com/security/cve?package=ncurses","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ncurses","debian":"https://tracker.debian.org/pkg/ncurses","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"6.1+20180210-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"6.1+20180210-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.1+20180210-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10753","published":"2018-05-05T02:29:00","updated_at":"2025-08-25T22:43:40.892185+00:00","description":"\nStack-based buffer overflow in the delayed_output function in music.c in\nabcm2ps through 8.13.20 allows remote attackers to cause a denial of\nservice (application crash) or possibly have unspecified other impact.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/leesavide/abcm2ps/issues/16","https://github.com/leesavide/abcm2ps/commit/fd956e19f88ee32f8ec4aece5901400b06e80bcc","https://drive.google.com/drive/u/2/folders/1DvBEh5D-eW4UkvX3947UQh62i7hUIFN1","https://ubuntu.com/security/notices/USN-5961-1","https://www.cve.org/CVERecord?id=CVE-2018-10753"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=897966"],"patches":{"abcm2ps":[]},"tags":{},"packages":[{"name":"abcm2ps","source":"https://ubuntu.com/security/cve?package=abcm2ps","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=abcm2ps","debian":"https://tracker.debian.org/pkg/abcm2ps","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"7.8.9-1+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"8.14.2-0.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.8.9-1ubuntu0.16.04.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-5961-1"],"notices":[{"id":"USN-5961-1","title":"abcm2ps vulnerabilities","summary":"Several security issues were fixed in abcm2ps.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-16T14:18:37.293881","description":"It was discovered that abcm2ps incorrectly\nhandled memory when parsing specially crafted ABC files.\nAn attacker could use this issue to cause abcm2ps to crash,\nleading to a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 ESM\nand Ubuntu 18.04 LTS. \n(CVE-2018-10753, CVE-2018-10771, CVE-2019-1010069)\n\nChiba of Topsec Alpha Lab discovered that abcm2ps incorrectly\nhandled memory when parsing specially crafted ABC files.\nAn attacker could use this issue to cause abcm2ps to crash,\nleading to a denial of service.\n(CVE-2021-32434, CVE-2021-32435, CVE-2021-32436)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"abcm2ps","version":"8.14.11-0.1ubuntu0.1~esm1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"8.14.11-0.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"abcm2ps","version":"7.8.9-1+deb9u1build0.18.04.1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"7.8.9-1+deb9u1build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":"https://launchpad.net/ubuntu/+source/abcm2ps/7.8.9-1+deb9u1build0.18.04.1","pocket":"security"}],"focal":[{"name":"abcm2ps","version":"8.14.6-0.1ubuntu0.1~esm1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"8.14.6-0.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"abcm2ps","version":"7.8.9-1ubuntu0.16.04.1~esm1","description":"Translates ABC music description files to PostScript","is_source":true},{"name":"abcm2ps","version":"7.8.9-1ubuntu0.16.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/abcm2ps","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-32435","CVE-2018-10771","CVE-2019-1010069","CVE-2021-32434","CVE-2021-32436","CVE-2018-10753"]}]},{"id":"CVE-2018-9154","published":"2018-05-04T21:29:00","updated_at":"2025-08-01T17:20:05.255050+00:00","description":"\nThere is a reachable abort in the function jpc_dec_process_sot in\nlibjasper/jpc/jpc_dec.c of JasPer 2.0.14 that will lead to a remote denial\nof service attack by triggering an unexpected jas_alloc2 return value, a\ndifferent vulnerability than CVE-2017-13745.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2018-08-03, no upstream fix"}],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://drive.google.com/drive/u/2/folders/1YuxdfbZrw79kfzoQz0PpxIutZ7pkf_kW","https://www.cve.org/CVERecord?id=CVE-2018-9154"],"bugs":[""],"patches":{"jasper":[]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was deferred","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was deferred [2018-08-03]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-2233","published":"2018-05-04T20:29:00","updated_at":"2025-08-25T20:51:29.217904+00:00","description":"\nAnsible before 1.2.1 makes it easier for remote attackers to conduct\nman-in-the-middle attacks by leveraging failure to cache SSH host keys.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2013-2233"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=714822","https://github.com/ansible/ansible/issues/857","https://bugs.launchpad.net/ubuntu/+source/ansible/+bug/1256068"],"patches":{"ansible":[]},"tags":{},"packages":[{"name":"ansible","source":"https://ubuntu.com/security/cve?package=ansible","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ansible","debian":"https://tracker.debian.org/pkg/ansible","statuses":[{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"quantal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"raring","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.0.0.2-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-0704","published":"2018-05-04T20:29:00","updated_at":"2025-08-25T20:08:37.500137+00:00","description":"\n389 Directory Server 1.2.7.5, when built with mozldap, allows remote\nattackers to cause a denial of service (replica crash) by sending an empty\nmodify request.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=675320","https://bugzilla.redhat.com/show_bug.cgi?id=676876","https://www.cve.org/CVERecord?id=CVE-2011-0704"],"bugs":[""],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.7.10-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.0.11-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.3.4.9-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.4.3.6-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.4.4.11-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.4.4.11-2build1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.3.2.16-0ubuntu1]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10733","published":"2018-05-04T17:29:00","updated_at":"2025-08-18T17:07:27.675700+00:00","description":"\nThere is a heap-based buffer over-read in the function ft_font_face_hash of\ngxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a\nremote denial of service attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-10733"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=897954","https://bugzilla.redhat.com/show_bug.cgi?id=1574844","https://bugs.launchpad.net/ubuntu/+source/libgxps/+bug/1797785"],"patches":{"libgxps":["upstream: https://git.gnome.org/browse/libgxps/commit/?id=b458226e162fe1ffe7acb4230c114a52ada5131b","upstream: https://git.gnome.org/browse/libgxps/commit/?id=133fe2a96e020d4ca65c6f64fb28a404050ebbfd"]},"tags":{},"packages":[{"name":"libgxps","source":"https://ubuntu.com/security/cve?package=libgxps","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgxps","debian":"https://tracker.debian.org/pkg/libgxps","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.3.0-3","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.3.0-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10689","published":"2018-05-03T07:29:00","updated_at":"2025-08-25T22:43:40.892185+00:00","description":"\nblktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and\nAndroid, has a buffer overflow in the dev_map_read function in btt/devmap.c\nbecause the device and devno arrays are too small, as demonstrated by an\ninvalid free when using the btt program with a crafted file.","ubuntu_description":"\nIt was discovered a buffer overflow in the blktrace utility. An attacker\ncould use this vulnerability to cause a DoS or possibly execute arbitrary\ncode.","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://git.kernel.org/pub/scm/linux/kernel/git/axboe/blktrace.git/commit/?id=d61ff409cb4dda31386373d706ea0cfb1aaac5b7","https://www.spinics.net/lists/linux-btrace/msg00847.html","http://git.kernel.dk/?p=blktrace.git;a=log;h=d61ff409cb4dda31386373d706ea0cfb1aaac5b7","https://www.cve.org/CVERecord?id=CVE-2018-10689"],"bugs":[""],"patches":{"blktrace":["upstream: http://git.kernel.dk/?p=blktrace.git;a=commitdiff;h=d61ff409cb4dda31386373d706ea0cfb1aaac5b7"]},"tags":{},"packages":[{"name":"blktrace","source":"https://ubuntu.com/security/cve?package=blktrace","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=blktrace","debian":"https://tracker.debian.org/pkg/blktrace","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.1.0-2+deb9u1build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.2.0-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.5-1+deb8u1build0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.5-1+deb8u1, 1.1.0-2+deb9u1, 1.2.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.1.0-2+deb9u1build0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10722","published":"2018-05-02T23:29:00","updated_at":"2025-08-26T11:53:50.029867+00:00","description":"\npartclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer\noverflow vulnerability due to insufficient validation of the FAT\nsuperblock, related to the mark_reserved_sectors function. An attacker may\nbe able to execute arbitrary code in the context of the user running the\naffected application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://david.gnedt.at/blog/2016/11/14/advisory-partclone-fat-bitmap-heap-overflow/","https://github.com/Thomas-Tsai/partclone/issues/71","https://www.cve.org/CVERecord?id=CVE-2016-10722"],"bugs":[""],"patches":{"partclone":[]},"tags":{},"packages":[{"name":"partclone","source":"https://ubuntu.com/security/cve?package=partclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=partclone","debian":"https://tracker.debian.org/pkg/partclone","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"0.3.6-2build1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.88-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":52980,"limit":20,"total_results":79316}