{"cves":[{"id":"CVE-2017-1000419","published":"2018-01-02T19:29:00","updated_at":"2025-07-17T16:42:54.213282+00:00","description":"\nphpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function\nresulting allowing an attacker to perform port scanning, requesting\ninternal content and potentially attacking such internal services via the\nweb application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.phpbb.com/community/viewtopic.php?f=14&p=14782136","https://www.sec-consult.com/en/blog/advisories/phpbb-server-side-request-forgery-vulnerability/index.html","https://www.cve.org/CVERecord?id=CVE-2017-1000419"],"bugs":[""],"patches":{"phpbb3":[]},"tags":{},"packages":[{"name":"phpbb3","source":"https://ubuntu.com/security/cve?package=phpbb3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=phpbb3","debian":"https://tracker.debian.org/pkg/phpbb3","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000458","published":"2018-01-02T18:29:00","updated_at":"2025-08-26T11:57:01.649700+00:00","description":"\nBro before Bro v2.5.2 is vulnerable to an out of bounds write in the\nContentLine analyzer allowing remote attackers to cause a denial of service\n(crash) and possibly other exploitation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://bro-tracker.atlassian.net/browse/BIT-1856","https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282","https://www.cve.org/CVERecord?id=CVE-2017-1000458"],"bugs":[""],"patches":{"bro":["upstream: https://github.com/bro/bro/commit/6c0f101a62489b1c5927b4ed63b0e1d37db40282"]},"tags":{},"packages":[{"name":"bro","source":"https://ubuntu.com/security/cve?package=bro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bro","debian":"https://tracker.debian.org/pkg/bro","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.5.3-1build1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.5.3-1build1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.5.3-1build1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.5.3-1build1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.2-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000418","published":"2018-01-02T18:29:00","updated_at":"2025-07-17T16:42:54.213282+00:00","description":"\nThe WildMidi_Open function in WildMIDI since commit\nd8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a\ndenial of service (heap-based buffer overflow and application crash) or\npossibly have unspecified other impact via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Mindwerks/wildmidi/commit/814f31d8eceda8401eb812fc2e94ed143fdad0ab","https://github.com/Mindwerks/wildmidi/issues/178","https://www.cve.org/CVERecord?id=CVE-2017-1000418"],"bugs":[""],"patches":{"wildmidi":[]},"tags":{},"packages":[{"name":"wildmidi","source":"https://ubuntu.com/security/cve?package=wildmidi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wildmidi","debian":"https://tracker.debian.org/pkg/wildmidi","statuses":[{"release_codename":"bionic","status":"not-affected","description":"0.4.2-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.4.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.4.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000450","published":"2018-01-02T17:29:00","updated_at":"2025-08-25T22:18:59.021185+00:00","description":"\nIn opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and\nFillUniGray do not check the input length, which can lead to integer\noverflow. If the image is from remote, may lead to remote code execution or\ndenial of service. This affects Opencv 3.3 and earlier.","ubuntu_description":"\nIt was discovered that OpenCV incorrectly handled certain image files.\nAn attacker could possibly use this issue to cause a denial of service,\nexecute arbitrary code or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/blendin/pocs/blob/master/opencv/0.OOB_Write_FillUniColor","https://github.com/opencv/opencv/issues/9723","https://www.cve.org/CVERecord?id=CVE-2017-1000450"],"bugs":[""],"patches":{"opencv":[]},"tags":{},"packages":[{"name":"opencv","source":"https://ubuntu.com/security/cve?package=opencv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opencv","debian":"https://tracker.debian.org/pkg/opencv","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.9.1+dfsg-1+deb8u2, 2.3.1-11+deb7u2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.4.9.1+dfsg-1.5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.2.0+dfsg-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.4.8+dfsg1-2ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000456","published":"2018-01-02T00:00:00","updated_at":"2025-08-25T22:18:59.021185+00:00","description":"\nfreedesktop.org libpoppler 0.60.1 fails to validate boundaries in\nTextPool::addWord, leading to overflow in subsequent calculations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3517-1","https://www.cve.org/CVERecord?id=CVE-2017-1000456"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=103116"],"patches":{"poppler":["upstream: https://cgit.freedesktop.org/poppler/poppler/commit/?id=7ee9dadef37b20bca707a6b1e858e17d191e368b"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"artful","status":"released","description":"0.57.0-2ubuntu4.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.61","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.48.0-2ubuntu2.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-3517-1"],"notices":[{"id":"USN-3517-1","title":"poppler vulnerabilities","summary":"Several security issues were fixed in poppler.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-01-08T14:03:12.426598","description":"It was discovered that poppler incorrectly handled certain files.\nIf a user or automated system were tricked into opening a crafted PDF\nfile, an attacker could execute arbitrary. (CVE-2017-1000456)\n\nIt was discovered that poppler incorrectly handled certain files.\nIf a user or automated system were tricked into opening a crafted PDF\nfile, an attacker could cause a denial of service. This issue only\naffected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2017-14976)\n","is_hidden":false,"release_packages":{"artful":[{"name":"poppler","version":"0.57.0-2ubuntu4.2","description":"PDF rendering library","is_source":true},{"name":"libpoppler68","version":"0.57.0-2ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.57.0-2ubuntu4.2"},{"name":"poppler-utils","version":"0.57.0-2ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.57.0-2ubuntu4.2"}],"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.9","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.9","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.6","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.6","pocket":"security"}],"zesty":[{"name":"poppler","version":"0.48.0-2ubuntu2.5","description":"PDF rendering library","is_source":true},{"name":"libpoppler64","version":"0.48.0-2ubuntu2.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.5"},{"name":"poppler-utils","version":"0.48.0-2ubuntu2.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.5"}]},"type":"USN","cves_ids":["CVE-2017-1000456","CVE-2017-14976"]}]},{"id":"CVE-2017-1000445","published":"2018-01-02T00:00:00","updated_at":"2025-08-25T22:18:59.021185+00:00","description":"\nImageMagick 7.0.7-1 and older version are vulnerable to null pointer\ndereference in the MagickCore component and might lead to denial of service","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fixed by CVE-2017-1000445.patch in wheezy"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-1000445"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/775","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=886281"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/839a14e43d0c88db7b3fffe8aa4ec57d80c93623"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-1000433","published":"2018-01-02T00:00:00","updated_at":"2025-08-25T22:18:54.650381+00:00","description":"\npysaml2 version 4.4.0 and older accept any password when run with python\noptimizations enabled. This allows attackers to log in as any user without\nknowing their password.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/rohe/pysaml2/issues/451","https://ubuntu.com/security/notices/USN-3520-1","https://www.cve.org/CVERecord?id=CVE-2017-1000433"],"bugs":[""],"patches":{"python-pysaml2":["upstream: https://github.com/rohe/pysaml2/commit/efe27e2f40bf1c35d847f935ba74b4b86aa90fb5"]},"tags":{},"packages":[{"name":"python-pysaml2","source":"https://ubuntu.com/security/cve?package=python-pysaml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pysaml2","debian":"https://tracker.debian.org/pkg/python-pysaml2","statuses":[{"release_codename":"artful","status":"released","description":"3.0.0-3ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.0.0-3ubuntu1.16.04.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"3.0.0-3ubuntu1.17.04.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3520-1"],"notices":[{"id":"USN-3520-1","title":"PySAML2 vulnerability","summary":"PySAML2 could allow authentication without a password.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-01-08T16:19:37.807274","description":"It was discovered that PySAML2 incorrectly accepted any password when run\nwith python optimizations enabled. An attacker could use this issue to\nauthenticate as any user without a valid password.\n","is_hidden":false,"release_packages":{"artful":[{"name":"python-pysaml2","version":"3.0.0-3ubuntu2.2","description":"Pure python implementation of SAML2","is_source":true},{"name":"python-pysaml2","version":"3.0.0-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu2.2"},{"name":"python3-pysaml2","version":"3.0.0-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu2.2"}],"xenial":[{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.16.04.3","description":"Pure python implementation of SAML2","is_source":true},{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.16.04.3","pocket":"security"},{"name":"python-pysaml2-doc","version":"3.0.0-3ubuntu1.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.16.04.3","pocket":"security"},{"name":"python3-pysaml2","version":"3.0.0-3ubuntu1.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.16.04.3","pocket":"security"}],"zesty":[{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.17.04.3","description":"Pure python implementation of SAML2","is_source":true},{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.17.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.17.04.3"},{"name":"python3-pysaml2","version":"3.0.0-3ubuntu1.17.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.17.04.3"}]},"type":"USN","cves_ids":["CVE-2017-1000433"]}]},{"id":"CVE-2017-1000422","published":"2018-01-02T00:00:00","updated_at":"2025-08-25T22:18:54.650381+00:00","description":"\nGnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow\nin the gif_get_lzw function resulting in memory corruption and potential\ncode execution","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.gnome.org/show_bug.cgi?id=785973","https://ubuntu.com/security/notices/USN-3532-1","https://www.cve.org/CVERecord?id=CVE-2017-1000422"],"bugs":[""],"patches":{"gdk-pixbuf":["upstream: https://git.gnome.org/browse/gdk-pixbuf/commit/?id=0012e06"]},"tags":{},"packages":[{"name":"gdk-pixbuf","source":"https://ubuntu.com/security/cve?package=gdk-pixbuf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gdk-pixbuf","debian":"https://tracker.debian.org/pkg/gdk-pixbuf","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.36.11-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.30.7-0ubuntu1.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.36.11-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.32.2-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3532-1"],"notices":[{"id":"USN-3532-1","title":"GDK-PixBuf vulnerabilities","summary":"Several security issues were fixed in GDK-PixBuf.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2018-01-15T16:53:32.553059","description":"It was discoreved that GDK-PixBuf incorrectly handled certain gif images.\nAn attacker could use this to execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-1000422)\n\nAriel Zelivansky discovered that GDK-PixBuf incorrectly handled certain images.\nAn attacker could use this to cause a denial of service.\n(CVE-2017-6312, CVE-2017-6313)\n\nAriel Zelivansky discovered that GDK-PixBuf incorrectly handled large TIFF files.\nAn attacker could use this to cause a denial of service. (CVE-2017-6314)\n","is_hidden":false,"release_packages":{"artful":[{"name":"gdk-pixbuf","version":"2.36.11-1ubuntu0.1","description":"GDK Pixbuf library","is_source":true},{"name":"libgdk-pixbuf2.0-0","version":"2.36.11-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.36.11-1ubuntu0.1"}],"trusty":[{"name":"gdk-pixbuf","version":"2.30.7-0ubuntu1.8","description":"GDK Pixbuf library","is_source":true},{"name":"gir1.2-gdkpixbuf-2.0","version":"2.30.7-0ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.8","pocket":"security"},{"name":"libgdk-pixbuf2.0-0","version":"2.30.7-0ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.8","pocket":"security"},{"name":"libgdk-pixbuf2.0-0-udeb","version":"2.30.7-0ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.8","pocket":"security"},{"name":"libgdk-pixbuf2.0-common","version":"2.30.7-0ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.8","pocket":"security"},{"name":"libgdk-pixbuf2.0-dev","version":"2.30.7-0ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.8","pocket":"security"},{"name":"libgdk-pixbuf2.0-doc","version":"2.30.7-0ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.30.7-0ubuntu1.8","pocket":"security"}],"xenial":[{"name":"gdk-pixbuf","version":"2.32.2-1ubuntu1.4","description":"GDK Pixbuf library","is_source":true},{"name":"gir1.2-gdkpixbuf-2.0","version":"2.32.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.4","pocket":"security"},{"name":"libgdk-pixbuf2.0-0","version":"2.32.2-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.4","pocket":"security"},{"name":"libgdk-pixbuf2.0-0-udeb","version":"2.32.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.4","pocket":"security"},{"name":"libgdk-pixbuf2.0-common","version":"2.32.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.4","pocket":"security"},{"name":"libgdk-pixbuf2.0-dev","version":"2.32.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.4","pocket":"security"},{"name":"libgdk-pixbuf2.0-doc","version":"2.32.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf","version_link":"https://launchpad.net/ubuntu/+source/gdk-pixbuf/2.32.2-1ubuntu1.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000422","CVE-2017-6312","CVE-2017-6313","CVE-2017-6314"]}]},{"id":"CVE-2017-18009","published":"2018-01-01T08:29:00","updated_at":"2025-08-25T22:29:14.232082+00:00","description":"\nIn OpenCV 3.3.1, a heap-based buffer over-read exists in the function\ncv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/opencv/opencv/issues/10479","https://ubuntu.com/security/notices/USN-4818-1","https://www.cve.org/CVERecord?id=CVE-2017-18009"],"bugs":[""],"patches":{"opencv":[]},"tags":{},"packages":[{"name":"opencv","source":"https://ubuntu.com/security/cve?package=opencv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opencv","debian":"https://tracker.debian.org/pkg/opencv","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.2.0+dfsg-4ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.1, 3.4.4+dfsg-1~exp1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.1.2+dfsg-4ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-4818-1"],"notices":[{"id":"USN-4818-1","title":"OpenCV vulnerabilities","summary":"Several security issues were fixed in OpenCV.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-09-28T14:52:46.781826","description":"It was discovered that OpenCV did not properly manage certain\nobjects, leading to a divide-by-zero. If a user were tricked into\nloading a specially crafted file, a remote attacker could potentially use\nthis issue to cause a denial of service or possibly execute arbitrary\ncode. (CVE-2019-15939)\n\nIt was discovered that OpenCV did not properly manage certain files,\nleading to an out of bounds read. If a user were tricked into loading\na specially crafted file, a remote attacker could potentially use this\nissue to make OpenCV crash, resulting in a denial of service. This issue\nwas only fixed in Ubuntu 18.04 ESM. (CVE-2019-14491, CVE-2019-14492)\n\nIt was discovered that OpenCV did not properly manage certain XML data,\nleading to a NULL pointer dereference. If a user were tricked into\nloading a specially crafted file, a remote attacker could potentially use\nthis issue to make OpenCV crash, resulting in a denial of service. This\nissue was only fixed in Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.\n(CVE-2019-14493)\n\nIt was discovered that OpenCV did not properly manage certain files,\nleading to a heap-based buffer overflow. If a user were tricked into\nloading a specially crafted file, a remote attacker could potentially use\nthis issue to cause a denial of service or possibly execute arbitrary code.\nThis issue only affected Ubuntu 18.04 ESM. (CVE-2017-18009)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"opencv","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","description":"computer vision library","is_source":true},{"name":"libopencv-ocl-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-superres2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"python-opencv","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-ts2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-features2d-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-photo-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libcv-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-video2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-flann-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-flann2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-ts-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-gpu-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-gpu2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-ml-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libcvaux-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-videostab-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-imgproc2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-superres-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libcvaux2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-stitching-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-imgproc-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-stitching2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"opencv-doc","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-calib3d-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libhighgui2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-objdetect2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"opencv-data","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-ml2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv2.4-jni","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-contrib-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libcv2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-calib3d2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-contrib2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-video-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv2.4-java","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-highgui-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-highgui2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-photo2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-features2d2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-legacy2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-objdetect-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-core2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libhighgui-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-ocl2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-core-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-legacy-dev","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"},{"name":"libopencv-videostab2.4","version":"2.4.8+dfsg1-2ubuntu1.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-infra"}],"bionic":[{"name":"opencv","version":"3.2.0+dfsg-4ubuntu0.1+esm3","description":"computer vision library","is_source":true},{"name":"libopencv-imgcodecs3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-features2d-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-videoio-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-photo-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-video3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-flann-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-superres-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ts-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-flann3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-stitching3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ml-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-imgproc3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-videoio3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-viz3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-videostab-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv3.2-java","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-photo3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-imgcodecs-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-stitching-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-imgproc-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"python-opencv","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv3.2-jni","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-superres3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-viz-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-calib3d-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"opencv-doc","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-objdetect3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"opencv-data","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ml3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-shape-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-calib3d3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-contrib-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-shape3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-video-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-highgui3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-highgui-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-features2d3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-core3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-contrib3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-objdetect-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"python3-opencv","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-core-dev","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-videostab3.2","version":"3.2.0+dfsg-4ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"opencv","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","description":"computer vision library","is_source":true},{"name":"libopencv-ocl-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ml2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-features2d-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-photo-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libcv-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-flann-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-contrib2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-flann2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ts-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-gpu-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ml-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-highgui2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libcvaux-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-videostab-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-objdetect-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libcvaux2.4","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ocl2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-stitching-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-imgproc-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-photo2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"python-opencv","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-objdetect2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"opencv-doc","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-calib3d-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-superres2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libhighgui2.4","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-video2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-features2d2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-videostab2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-ts2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"opencv-data","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-legacy2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-gpu2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-core2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-contrib-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libcv2.4","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-video-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv2.4-jni","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv2.4-java","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-highgui-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-imgproc2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-stitching2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-calib3d2.4v5","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libhighgui-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-core-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-superres-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"},{"name":"libopencv-legacy-dev","version":"2.4.9.1+dfsg-1.5ubuntu1.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/opencv","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-15939","CVE-2019-14491","CVE-2019-14493","CVE-2019-14492","CVE-2017-18009"]}]},{"id":"CVE-2017-18013","published":"2018-01-01T00:00:00","updated_at":"2025-08-25T22:29:14.232082+00:00","description":"\nIn LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c\nTIFFPrintDirectory function, as demonstrated by a tiffinfo crash.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in https://gitlab.com/libtiff/libtiff/commit/7057734d986001b7fd6d2afde9667da7754ff2cc which is 4.0.9 only\nwe will not be fixing this issue in precise/esm"}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3602-1","https://ubuntu.com/security/notices/USN-3606-1","https://www.cve.org/CVERecord?id=CVE-2017-18013"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2770","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=885985"],"patches":{"tiff":["upstream: https://gitlab.com/libtiff/libtiff/commit/c6f41df7b581402dfba3c19a1e3df4454c551a01"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"released","description":"4.0.8-5ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.9-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3606-1","USN-3602-1"],"notices":[{"id":"USN-3606-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-26T11:50:26.215438","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"artful":[{"name":"tiff","version":"4.0.8-5ubuntu0.1","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-tools","version":"4.0.8-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.8-5ubuntu0.1"},{"name":"libtiff5","version":"4.0.8-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.8-5ubuntu0.1"}],"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.9","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.9","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.4","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-3186","CVE-2016-5102","CVE-2016-5318","CVE-2017-11613","CVE-2017-12944","CVE-2017-17095","CVE-2017-18013","CVE-2017-5563","CVE-2017-9117","CVE-2017-9147","CVE-2017-9935","CVE-2018-5784"]},{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2017-18008","published":"2018-01-01T00:00:00","updated_at":"2025-08-25T22:29:14.232082+00:00","description":"\nIn ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in\ncoders/pwp.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"not fixing memory leak in trusty and xenial"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-18008"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/921"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/1a5f95fc018a5667de5a9448aee9d7251b2eb952"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-18005","published":"2017-12-31T19:29:00","updated_at":"2025-08-25T22:29:14.232082+00:00","description":"\nExiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong\nfunction in value.cpp, related to crafted metadata in a TIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"can't reproduce with 0.25, upstream but says post 0.26 master"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-18005"],"bugs":["https://github.com/Exiv2/exiv2/issues/168","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=885981"],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/pull/199","upstream: https://github.com/Exiv2/exiv2/commit/a07f0278a6e62c14619af784518fbe2eed99c1b0","upstream: https://github.com/Exiv2/exiv2/commit/0c9dcbd7323fd347e872a185523957123da80a05","upstream: https://github.com/Exiv2/exiv2/commit/06bd9c4dbd866e3e56c8a021a18a156002414c9b","upstream: https://github.com/Exiv2/exiv2/commit/235e56cf6b47a508e3f13810e91f296be6466199","upstream: https://github.com/Exiv2/exiv2/commit/182a12a136a7422b2a40ab6c333e1cedd4d566d1"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.25-3.1ubuntu0.18.04.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.25-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.25-2.1ubuntu16.04.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [0.23-1ubuntu2.2]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7165","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:37:13.423482+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 11.2 is\naffected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is\naffected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is\naffected. watchOS before 4.2 is affected. The issue involves the \"WebKit\"\ncomponent. It allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0002.html","https://ubuntu.com/security/notices/USN-3551-1","https://www.cve.org/CVERecord?id=CVE-2017-7165"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"2.18.6-0ubuntu0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.18.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3551-1"],"notices":[{"id":"USN-3551-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-01-30T21:05:46.260107","description":"Multiple security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit these to cause a\ndenial of service, spoof the user interface, or execute arbitrary code.\n(CVE-2018-4088, CVE-2018-4096, CVE-2017-7153, CVE-2017-7160,\nCVE-2017-7161, CVE-2017-7165, CVE-2017-13884, CVE-2017-13885)\n","is_hidden":false,"release_packages":{"artful":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.17.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"}],"xenial":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-13884","CVE-2017-13885","CVE-2017-7153","CVE-2017-7160","CVE-2017-7161","CVE-2017-7165","CVE-2018-4088","CVE-2018-4096"]}]},{"id":"CVE-2017-7161","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:37:13.423482+00:00","description":"\nAn issue was discovered in certain Apple products. Safari before 11.0.2 is\naffected. The issue involves the \"WebKit Web Inspector\" component. It\nallows remote attackers to execute arbitrary code via special characters\nthat trigger command injection.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0002.html","https://ubuntu.com/security/notices/USN-3551-1","https://www.cve.org/CVERecord?id=CVE-2017-7161"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"2.18.6-0ubuntu0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.18.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3551-1"],"notices":[{"id":"USN-3551-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-01-30T21:05:46.260107","description":"Multiple security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit these to cause a\ndenial of service, spoof the user interface, or execute arbitrary code.\n(CVE-2018-4088, CVE-2018-4096, CVE-2017-7153, CVE-2017-7160,\nCVE-2017-7161, CVE-2017-7165, CVE-2017-13884, CVE-2017-13885)\n","is_hidden":false,"release_packages":{"artful":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.17.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"}],"xenial":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-13884","CVE-2017-13885","CVE-2017-7153","CVE-2017-7160","CVE-2017-7161","CVE-2017-7165","CVE-2018-4088","CVE-2018-4096"]}]},{"id":"CVE-2017-5934","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:35:27.038421+00:00","description":"\nCross-site scripting (XSS) vulnerability in the link dialogue in GUI editor\nin MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web\nscript or HTML via unspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/moinwiki/moin-1.9/commit/70955a8eae091cc88fd9a6e510177e70289ec024","https://ubuntu.com/security/notices/USN-3794-1","https://www.cve.org/CVERecord?id=CVE-2017-5934"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=910776"],"patches":{"moin":[]},"tags":{},"packages":[{"name":"moin","source":"https://ubuntu.com/security/cve?package=moin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moin","debian":"https://tracker.debian.org/pkg/moin","statuses":[{"release_codename":"bionic","status":"released","description":"1.9.9-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.9.9-1ubuntu1.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.9.9-1+deb9u1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.9.7-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.9.8-1ubuntu1.16.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3794-1"],"notices":[{"id":"USN-3794-1","title":"MoinMoin vulnerability","summary":"MoinMoin could be made to expose sensitive information if it\nreceived a specially crafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-10-16T13:19:07.361224","description":"It was discovered that MoinMoin incorrectly handled certain inputs.\nAn attacker could possibly use this issue to access sensitive information.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"moin","version":"1.9.9-1ubuntu1.1","description":"Collaborative hypertext environment","is_source":true},{"name":"python-moinmoin","version":"1.9.9-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.9.9-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"moin","version":"1.9.7-1ubuntu2.2","description":"Collaborative hypertext environment","is_source":true},{"name":"python-moinmoin","version":"1.9.7-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.9.7-1ubuntu2.2","pocket":"security"}],"xenial":[{"name":"moin","version":"1.9.8-1ubuntu1.16.04.2","description":"Collaborative hypertext environment","is_source":true},{"name":"python-moinmoin","version":"1.9.8-1ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/moin","version_link":"https://launchpad.net/ubuntu/+source/moin/1.9.8-1ubuntu1.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-5934"]}]},{"id":"CVE-2017-3144","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:32:04.140595+00:00","description":"\nA vulnerability stemming from failure to properly clean up closed OMAPI\nconnections can lead to exhaustion of the pool of socket descriptors\navailable to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0\nto 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well\nbeyond their end-of-life (EOL). Releases prior to 4.1.0 have not been\ntested.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"DoS over OMAPI port only, see ISC kb article\nfor workarounds, or properly limit access to ports"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://kb.isc.org/article/AA-01541","https://ubuntu.com/security/notices/USN-3586-1","https://www.cve.org/CVERecord?id=CVE-2017-3144"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1522918","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=887413"],"patches":{"isc-dhcp":["upstream: https://source.isc.org/cgi-bin/gitweb.cgi?p=dhcp.git;a=commit;h=1a6b62fe17a42b00fa234d06b6dfde3d03451894"]},"tags":{},"packages":[{"name":"isc-dhcp","source":"https://ubuntu.com/security/cve?package=isc-dhcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=isc-dhcp","debian":"https://tracker.debian.org/pkg/isc-dhcp","statuses":[{"release_codename":"groovy","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"4.3.5-3ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.3.5-3ubuntu5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.2.4-7ubuntu12.12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.3.3-5ubuntu12.9","component":null,"pocket":"security"}]}],"notices_ids":["USN-3586-1"],"notices":[{"id":"USN-3586-1","title":"DHCP vulnerabilities","summary":"Several security issues were fixed in DHCP.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-01T17:47:25.583959","description":"Konstantin Orekhov discovered that the DHCP server incorrectly handled a\nlarge number of concurrent TCP sessions. A remote attacker could possibly\nuse this issue to cause a denial of service. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-2774)\n\nIt was discovered that the DHCP server incorrectly handled socket\ndescriptors. A remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2017-3144)\n\nFelix Wilhelm discovered that the DHCP client incorrectly handled certain\nmalformed responses. A remote attacker could use this issue to cause the\nDHCP client to crash, resulting in a denial of service, or possibly execute\narbitrary code. In the default installation, attackers would be isolated by\nthe dhclient AppArmor profile. (CVE-2018-5732)\n\nFelix Wilhelm discovered that the DHCP server incorrectly handled reference\ncounting. A remote attacker could possibly use this issue to cause the DHCP\nserver to crash, resulting in a denial of service. (CVE-2018-5733)\n","is_hidden":false,"release_packages":{"artful":[{"name":"isc-dhcp","version":"4.3.5-3ubuntu2.2","description":"DHCP server and client","is_source":true},{"name":"isc-dhcp-client","version":"4.3.5-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.5-3ubuntu2.2"},{"name":"isc-dhcp-relay","version":"4.3.5-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.5-3ubuntu2.2"},{"name":"isc-dhcp-server","version":"4.3.5-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.5-3ubuntu2.2"},{"name":"isc-dhcp-server-ldap","version":"4.3.5-3ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.5-3ubuntu2.2"}],"trusty":[{"name":"isc-dhcp","version":"4.2.4-7ubuntu12.12","description":"DHCP server and client","is_source":true},{"name":"isc-dhcp-client","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-client-noddns","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-client-udeb","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-common","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-dev","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-relay","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-server","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"},{"name":"isc-dhcp-server-ldap","version":"4.2.4-7ubuntu12.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.2.4-7ubuntu12.12","pocket":"security"}],"xenial":[{"name":"isc-dhcp","version":"4.3.3-5ubuntu12.9","description":"DHCP server and client","is_source":true},{"name":"isc-dhcp-client","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-client-ddns","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-client-udeb","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-common","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-dev","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-relay","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-server","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"},{"name":"isc-dhcp-server-ldap","version":"4.3.3-5ubuntu12.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/isc-dhcp","version_link":"https://launchpad.net/ubuntu/+source/isc-dhcp/4.3.3-5ubuntu12.9","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-2774","CVE-2017-3144","CVE-2018-5732","CVE-2018-5733"]}]},{"id":"CVE-2017-13885","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:24:43.194923+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 11.2 is\naffected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is\naffected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is\naffected. The issue involves the \"WebKit\" component. It allows remote\nattackers to execute arbitrary code or cause a denial of service (memory\ncorruption and application crash) via a crafted web site.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0002.html","https://ubuntu.com/security/notices/USN-3551-1","https://www.cve.org/CVERecord?id=CVE-2017-13885"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"artful","status":"released","description":"2.18.6-0ubuntu0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.18.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3551-1"],"notices":[{"id":"USN-3551-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-01-30T21:05:46.260107","description":"Multiple security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit these to cause a\ndenial of service, spoof the user interface, or execute arbitrary code.\n(CVE-2018-4088, CVE-2018-4096, CVE-2017-7153, CVE-2017-7160,\nCVE-2017-7161, CVE-2017-7165, CVE-2017-13884, CVE-2017-13885)\n","is_hidden":false,"release_packages":{"artful":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.17.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"}],"xenial":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-13884","CVE-2017-13885","CVE-2017-7153","CVE-2017-7160","CVE-2017-7161","CVE-2017-7165","CVE-2018-4088","CVE-2018-4096"]}]},{"id":"CVE-2017-13884","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:24:38.686947+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 11.2 is\naffected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is\naffected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is\naffected. watchOS before 4.2 is affected. The issue involves the \"WebKit\"\ncomponent. It allows remote attackers to execute arbitrary code or cause a\ndenial of service (memory corruption and application crash) via a crafted\nweb site.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2018-0002.html","https://ubuntu.com/security/notices/USN-3551-1","https://www.cve.org/CVERecord?id=CVE-2017-13884"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"2.18.6-0ubuntu0.17.10.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.18.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.18.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.18.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3551-1"],"notices":[{"id":"USN-3551-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2018-01-30T21:05:46.260107","description":"Multiple security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked in to opening a specially\ncrafted website, an attacker could potentially exploit these to cause a\ndenial of service, spoof the user interface, or execute arbitrary code.\n(CVE-2018-4088, CVE-2018-4096, CVE-2017-7153, CVE-2017-7160,\nCVE-2017-7161, CVE-2017-7165, CVE-2017-13884, CVE-2017-13885)\n","is_hidden":false,"release_packages":{"artful":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.17.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.17.10.1"}],"xenial":[{"name":"webkit2gtk","version":"2.18.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.18.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.18.6-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-13884","CVE-2017-13885","CVE-2017-7153","CVE-2017-7160","CVE-2017-7161","CVE-2017-7165","CVE-2018-4088","CVE-2018-4096"]}]},{"id":"CVE-2017-10689","published":"2017-12-31T00:00:00","updated_at":"2025-08-25T22:19:44.813240+00:00","description":"\nIn previous versions of Puppet Agent it was possible to install a module\nwith world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a\nfix to this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://puppet.com/security/cve/CVE-2017-10689","https://ubuntu.com/security/notices/USN-3567-1","https://www.cve.org/CVERecord?id=CVE-2017-10689","https://ubuntu.com/security/notices/USN-4804-1"],"bugs":["https://tickets.puppetlabs.com/browse/PUP-7866"],"patches":{"puppet":["upstream: https://github.com/puppetlabs/puppet/commit/17d9e02da3882e44c1876e2805cf9708481715ee","upstream: https://github.com/puppetlabs/puppet/commit/983154f7e29a2a50d416d889a6fed012b9b12399"]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.4.3-1ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.8.5-2ubuntu0.1+esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-3567-1","USN-4804-1"],"notices":[{"id":"USN-3567-1","title":"Puppet vulnerability","summary":"Puppet could be made to crash or run programs.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-02-12T15:34:35.485195","description":"It was discovered that Puppet incorrectly handled permissions when\nunpacking certain tarballs. A local user could possibly use this issue to\nexecute arbitrary code.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"puppet","version":"3.4.3-1ubuntu1.3","description":"Centralized configuration management","is_source":true},{"name":"puppet","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"puppet-common","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"puppet-el","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"puppet-testsuite","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"puppetmaster","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"puppetmaster-common","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"puppetmaster-passenger","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"},{"name":"vim-puppet","version":"3.4.3-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/3.4.3-1ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10689"]},{"id":"USN-4804-1","title":"Puppet vulnerabilities","summary":"Several security issues were fixed in Puppet.\n","instructions":"After a standard system update you need to restart Puppet to make\nall the necessary changes.\n","references":[],"published":"2021-03-15T21:31:34.197385","description":"It was discovered that Puppet installed modules with world writable\npermissions. An attacker could use this vulnerability to execute arbitrary\ncode or cause a denial of service. (CVE-2017-10689)\n\nIt was discovered that Puppet could be used to force YAML deserialization in an\nunsafe manner. A remote attacker could use this vulnerability for remote code\nexecution. (CVE-2017-2295)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"puppet","version":"3.8.5-2ubuntu0.1+esm1","description":"Centralized configuration management","is_source":true},{"name":"puppetmaster-common","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"puppetmaster","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"puppet-testsuite","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"puppet","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"puppet-common","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"puppet-el","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"puppetmaster-passenger","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"},{"name":"vim-puppet","version":"3.8.5-2ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-10689","CVE-2017-2295"]}]},{"id":"CVE-2017-17997","published":"2017-12-30T07:29:00","updated_at":"2025-08-25T22:29:14.232082+00:00","description":"\nIn Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and\ncrashes. This was addressed in epan/dissectors/packet-mrdisc.c by\nvalidating an IPv4 address. This vulnerability is similar to CVE-2017-9343.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14299","https://code.wireshark.org/review/#/c/25063/","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=80a695869c9aef2fb473d9361da068022be7cb50","https://www.cve.org/CVERecord?id=CVE-2017-17997"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.4.2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.6.3-1~ubuntu18.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.6.3-1~ubuntu14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.6.3-1~ubuntu16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":54220,"limit":20,"total_results":79316}