{"cves":[{"id":"CVE-2017-9806","published":"2017-11-20T17:29:00","updated_at":"2025-08-25T22:42:09.396363+00:00","description":"\nA vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and\nspecifically in the WW8Fonts Constructor, allows attackers to craft\nmalicious documents that cause denial of service (memory corruption and\napplication crash) potentially resulting in arbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.talosintelligence.com/reports/TALOS-2017-0295","https://www.libreoffice.org/about-us/security/advisories/CVE-2017-9806","https://gerrit.libreoffice.org/gitweb?p=core.git;a=commitdiff_plain;h=bb494d6bd8c5868f34bd8f9444ed3eb401145f10","https://www.cve.org/CVERecord?id=CVE-2017-9806"],"bugs":[""],"patches":{"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:5.4.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.4.3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:5.1.6~rc2-0ubuntu1~xenial2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:5.3.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [1:4.2.8-0ubuntu5.1]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16898","published":"2017-11-20T17:29:00","updated_at":"2025-08-26T11:59:11.689219+00:00","description":"\nThe printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier\nis vulnerable to a global buffer overflow, which may allow attackers to\ncause a denial of service via a crafted file, a different vulnerability\nthan CVE-2016-9264.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/libming/libming/issues/75","https://www.cve.org/CVERecord?id=CVE-2017-16898"],"bugs":[""],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16896","published":"2017-11-20T16:29:00","updated_at":"2025-08-26T11:59:11.689219+00:00","description":"\nA SQL injection in classes/handler/public.php in the forgotpass component\nof Tiny Tiny RSS 17.4 exists via the login parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://discourse.tt-rss.org/t/sql-injection-in-forgotpass-fixed/669","https://git.tt-rss.org/git/tt-rss/commit/2352c320c2ed34ec7df1ad22f0c55a1b26489815","https://www.cve.org/CVERecord?id=CVE-2017-16896"],"bugs":[""],"patches":{"tt-rss":[]},"tags":{},"packages":[{"name":"tt-rss","source":"https://ubuntu.com/security/cve?package=tt-rss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tt-rss","debian":"https://tracker.debian.org/pkg/tt-rss","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"21~git20210204.b4cbc79+dfsg-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"17.4+git20180312+dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"21~git20210204.b4cbc79+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"21~git20210204.b4cbc79+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"21~git20210204.b4cbc79+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15110","published":"2017-11-20T14:29:00","updated_at":"2025-08-25T22:26:26.859633+00:00","description":"\nIn Moodle 3.x, students can find out email addresses of other students in\nthe same course. Using search on the Participants page, students could\nsearch email addresses of all participants regardless of email visibility.\nThis allows enumerating and guessing emails of other students.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://moodle.org/mod/forum/discuss.php?d=361784","https://www.cve.org/CVERecord?id=CVE-2017-15110"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16544","published":"2017-11-20T00:00:00","updated_at":"2025-08-25T22:27:44.522026+00:00","description":"\nIn the add_match function in libbb/lineedit.c in BusyBox through 1.27.2,\nthe tab autocomplete feature of the shell, used to get a list of filenames\nin a directory, does not sanitize filenames and results in executing any\nescape sequence in the terminal. This could potentially result in code\nexecution, arbitrary file writes, or other attacks.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.twistlock.com/2017/11/20/cve-2017-16544-busybox-autocompletion-vulnerability/","https://ubuntu.com/security/notices/USN-3935-1","https://www.cve.org/CVERecord?id=CVE-2017-16544"],"bugs":[""],"patches":{"busybox":["upstream: https://git.busybox.net/busybox/commit/?id=c3797d40a1c57352192c6106cc0f435e7d9c11e8"]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.21.0-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.22.0-15ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:1.27.2-1ubuntu4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3935-1"],"notices":[{"id":"USN-3935-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-03T11:59:48.636617","description":"Tyler Hicks discovered that BusyBox incorrectly handled symlinks inside tar\narchives. If a user or automated system were tricked into processing a\nspecially crafted tar archive, a remote attacker could overwrite arbitrary\nfiles outside of the current directory. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2011-5325)\n\nMathias Krause discovered that BusyBox incorrectly handled kernel module\nloading restrictions. A local attacker could possibly use this issue to\nbypass intended restrictions. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-9645)\n\nIt was discovered that BusyBox incorrectly handled certain ZIP archives. If\na user or automated system were tricked into processing a specially crafted\nZIP archive, a remote attacker could cause BusyBox to crash, leading to a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2015-9261)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain malformed domain names. A remote attacker could possibly use this\nissue to cause the DHCP client to crash, leading to a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-2147)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain 6RD options. A remote attacker could use this issue to cause the\nDHCP client to crash, leading to a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04\nLTS. (CVE-2016-2148)\n\nIt was discovered that BusyBox incorrectly handled certain bzip2 archives.\nIf a user or automated system were tricked into processing a specially\ncrafted bzip2 archive, a remote attacker could cause BusyBox to crash,\nleading to a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-15873)\n\nIt was discovered that BusyBox incorrectly handled tab completion. A local\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-16544)\n\nIt was discovered that the BusyBox wget utility incorrectly handled certain\nresponses. A remote attacker could use this issue to cause BusyBox to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2018-1000517)\n\nIt was discovered that the BusyBox DHCP utilities incorrectly handled\ncertain memory operations. A remote attacker could possibly use this issue\nto access sensitive information. (CVE-2018-20679, CVE-2019-5747)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"}],"cosmic":[{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"}],"trusty":[{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"}],"xenial":[{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2011-5325","CVE-2014-9645","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2017-15873","CVE-2017-16544","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747"]}]},{"id":"CVE-2017-16883","published":"2017-11-18T18:29:00","updated_at":"2025-08-26T11:59:11.689219+00:00","description":"\nThe outputSWF_TEXT_RECORD function in util/outputscript.c in libming <=\n0.4.8 is vulnerable to a NULL pointer dereference, which may allow\nattackers to cause a denial of service via a crafted swf file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/libming/libming/issues/77","https://www.cve.org/CVERecord?id=CVE-2017-16883"],"bugs":[""],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16882","published":"2017-11-18T18:29:00","updated_at":"2025-07-17T16:42:58.717220+00:00","description":"\nIcinga Core through 1.14.0 initially executes bin/icinga as root but\nsupports configuration options in which this file is owned by a non-root\naccount (and similarly can have etc/icinga.cfg owned by a non-root\naccount), which allows local users to gain privileges by leveraging access\nto this non-root account, a related issue to CVE-2017-14312. This also\naffects bin/icingastats, bin/ido2db, and bin/log2ido.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Icinga/icinga-core/issues/1601","https://www.cve.org/CVERecord?id=CVE-2017-16882"],"bugs":[""],"patches":{"icinga":[]},"tags":{},"packages":[{"name":"icinga","source":"https://ubuntu.com/security/cve?package=icinga","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=icinga","debian":"https://tracker.debian.org/pkg/icinga","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"files are owned by root","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"files are owned by root","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"files are owned by root","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [files are owned by root]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000128","published":"2017-11-17T22:29:00","updated_at":"2025-08-25T22:18:25.478107+00:00","description":"\nExiv2 0.26 contains a stack out of bounds read in JPEG2000 parser","ubuntu_description":"","notes":[{"author":"ratliff","note":"no crashes on trusty, xenial"},{"author":"mdeslaur","note":"doesn't crash on bionic either\nbased on the fixes below, it looks like this issue was\nintroduced by the following commit:\nhttps://github.com/Exiv2/exiv2/commit/699e1c744e50782e3ed7411cc6ac28260aa169c0\nwhich was added to 0.26"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/06/30/1","https://www.cve.org/CVERecord?id=CVE-2017-1000128"],"bugs":["https://github.com/Exiv2/exiv2/issues/177","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=897260"],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/commit/d09c4bb7cdc670ec7f1ffe2da4e378dfbbe45432","upstream: https://github.com/Exiv2/exiv2/commit/14ff034fb4efc557476f498af3874dc22e3801e8","upstream: https://github.com/Exiv2/exiv2/commit/22527f0927b687804f83f1cc1ec36e2f042c9f83","upstream: https://github.com/Exiv2/exiv2/commit/00f32316b2aa9664194fbc4fae11ee54808ebcf6"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000127","published":"2017-11-17T22:29:00","updated_at":"2025-08-25T22:18:25.478107+00:00","description":"\nExiv2 0.26 contains a heap buffer overflow in tiff parser","ubuntu_description":"","notes":[{"author":"ratliff","note":"no crashes on trusty, xenial"},{"author":"debian","note":"Vulnerable code introduced after 0.25"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/06/30/1","https://www.cve.org/CVERecord?id=CVE-2017-1000127"],"bugs":["https://github.com/Exiv2/exiv2/issues/176","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888863"],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000126","published":"2017-11-17T22:29:00","updated_at":"2025-08-25T22:18:25.478107+00:00","description":"\nexiv2 0.26 contains a Stack out of bounds read in webp parser","ubuntu_description":"","notes":[{"author":"ratliff","note":"no crashes on trusty, xenial and no fixes available"},{"author":"mdeslaur","note":"WebP support introduced in 0.26"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/06/30/1","https://www.cve.org/CVERecord?id=CVE-2017-1000126"],"bugs":["https://github.com/Exiv2/exiv2/issues/175","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=888864"],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000190","published":"2017-11-17T21:29:00","updated_at":"2025-09-15T19:44:22.870083+00:00","description":"\nSimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability\nresulting SSRF, information disclosure, DoS and so on.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"As of 11/09/2018, there is a comment on github recommending\nupdating to \"2.7.3\". This may be the fix version."}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/ngallagher/simplexml/issues/18","https://www.cve.org/CVERecord?id=CVE-2017-1000190"],"bugs":[""],"patches":{"simple-xml":[]},"tags":{},"packages":[{"name":"simple-xml","source":"https://ubuntu.com/security/cve?package=simple-xml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=simple-xml","debian":"https://tracker.debian.org/pkg/simple-xml","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.7.1-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16875","published":"2017-11-17T16:29:00","updated_at":"2026-03-24T22:02:33.459730+00:00","description":"\nAn issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP\nbefore 2.7.1. The ioqueue component may issue a double key unregistration\nafter an attacker initiates a socket connection with specific settings and\nsequences. Such double key unregistration will trigger an integer overflow,\nwhich may cause ioqueue backends to reject future key registrations.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://trac.pjsip.org/repos/ticket/2055","https://trac.pjsip.org/repos/changeset/5680","https://trac.pjsip.org/repos/milestone/release-2.7.1","https://www.cve.org/CVERecord?id=CVE-2017-16875","https://ubuntu.com/security/notices/USN-8122-1"],"bugs":[""],"patches":{"pjproject":["upstream: https://github.com/pjsip/pjproject/commit/f5900e790da36dd429e02c519608014c858f4b56"]},"tags":{},"packages":[{"name":"pjproject","source":"https://ubuntu.com/security/cve?package=pjproject","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pjproject","debian":"https://tracker.debian.org/pkg/pjproject","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1~dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-8122-1"],"notices":[{"id":"USN-8122-1","title":"PJSIP vulnerabilities","summary":"Several security issues were fixed in PJSIP.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-24T20:34:47.281461","description":"Youngsung Kim discovered that PJSIP did not properly parse numeric header\nfields in SIP messages. A remote attacker could use this issue to cause\nPJSIP to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-16872)\n\nPeter Koletzki discovered that PJSIP did not properly handle certain\nconnection requests. A remote attacker could possibly use this issue to\ncause PJSIP to enter an unrecoverable state and reject further connections,\nresulting in a denial of service. This issue only affected Ubuntu 16.04\nLTS. (CVE-2017-16875)\n\nAlfred Farrugia, Sandro Gauci, and Kevin Harwell discovered that PJSIP did\nnot properly parse certain SDP messages. A remote attacker could possibly\nuse this issue to cause PJSIP to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2018-1000098,\nCVE-2018-1000099)\n\nLauri Vänskä discovered that PJSIP did not verify hostnames when reusing\nTLS connections. If a remote attacker were able to intercept communication,\nthis flaw could possibly be exploited to view sensitive information.\n(CVE-2020-15260)\n\nIt was discovered that PJSIP did not properly handle certain sequences of\nSDP messages. A remote attacker could possibly use this issue to cause\nPJSIP to crash, resulting in a denial of service. (CVE-2021-21375)\n\nIt was discovered that the SSL socket implementation in PJSIP contained a\nrace condition. A remote attacker could possibly use this issue to cause\nPJSIP to crash, resulting in a denial of service. This issue was only\naddressed in Ubuntu 18.04 LTS. (CVE-2021-32686)\n\nIt was discovered that PJSIP did not properly parse certain STUN messages.\nA remote attacker could use this issue to cause PJSIP to crash, resulting\nin a denial of service, or possibly execute arbitrary code.\n(CVE-2021-37706)\n\nUriya Yavnieli discovered that PJSIP did not properly manage memory under\ncertain conditions. A remote attacker could use this issue to cause PJSIP\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2021-43299, CVE-2021-43300, CVE-2021-43301, CVE-2021-43302,\nCVE-2021-43303)\n\nIt was discovered that PJSIP did not properly manage memory when processing\nICE session credentials. A remote attacker could use this issue to cause\nPJSIP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2026-25994)","is_hidden":false,"release_packages":{"bionic":[{"name":"pjproject","version":"2.7.2~dfsg-1ubuntu0.1~esm1","description":"multimedia communication library","is_source":true},{"name":"libpj2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjlib-util2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-audiodev2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-codec2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-videodev2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjnath2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjproject-dev","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-simple2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-ua2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsua2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsua2-2v5","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"python-pjproject","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"pjproject","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","description":"multimedia communication library","is_source":true},{"name":"libpj2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjlib-util2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-audiodev2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-codec2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-videodev2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjnath2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjproject-dev","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-simple2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-ua2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsua2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-15260","CVE-2021-43300","CVE-2026-25994","CVE-2017-16872","CVE-2018-1000099","CVE-2021-37706","CVE-2021-43302","CVE-2021-43301","CVE-2018-1000098","CVE-2021-43303","CVE-2021-32686","CVE-2017-16875","CVE-2021-21375","CVE-2021-43299"]}]},{"id":"CVE-2017-1000211","published":"2017-11-17T15:29:00","updated_at":"2025-08-25T22:18:30.574492+00:00","description":"\nLynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML\nparser resulting in memory disclosure, because HTML_put_string() can append\na chunk onto itself.","ubuntu_description":"\nIt was discovered that Lynx incorrectly handled certain HTML files. A remote\nattacker could possibly use this issue to obtain sensitive information.","notes":[{"author":"tyhicks","note":"2.8.9dev.16 contained the fix"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/ThomasDickey/lynx-snapshots/commit/280a61b300a1614f6037efc0902ff7ecf17146e9","https://www.cve.org/CVERecord?id=CVE-2017-1000211","https://ubuntu.com/security/notices/USN-4800-1"],"bugs":[""],"patches":{"lynx":[]},"tags":{},"packages":[{"name":"lynx","source":"https://ubuntu.com/security/cve?package=lynx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lynx","debian":"https://tracker.debian.org/pkg/lynx","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.8.9dev16-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.8.9dev8-4ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4800-1"],"notices":[{"id":"USN-4800-1","title":"Lynx vulnerabilities","summary":"Several security issues were fixed in Lynx.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:24:24.708521","description":"It was discovered that Lynx incorrectly handled certain URLs. A remote attacker\ncould possibly use this issue to obtain sensitive information or other\nunspecified impact. This issue only affected Ubuntu 16.04 ESM.\n(CVE-2016-9179)\n\nIt was discovered that Lynx incorrectly handled certain HTML files. A remote\nattacker could possibly use this issue to obtain sensitive information.\nThis issue only affected Ubuntu 16.04 ESM. (CVE-2017-1000211)\n\nThorsten Glaser discovered that Lynx mishandles the userinfo subcomponents of\na URI. An attacker monitoring the network could discover cleartext\ncredentials because they may appear in SNI data. (CVE-2021-38165)","is_hidden":false,"release_packages":{"xenial":[{"name":"lynx","version":"2.8.9dev8-4ubuntu1+esm2","description":"classic non-graphical (text-mode) web browser","is_source":true},{"name":"lynx-cur","version":"2.8.9dev8-4ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx-common","version":"2.8.9dev8-4ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx","version":"2.8.9dev8-4ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"lynx","version":"2.8.9dev16-3ubuntu0.1~esm1","description":"classic non-graphical (text-mode) web browser","is_source":true},{"name":"lynx-common","version":"2.8.9dev16-3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx","version":"2.8.9dev16-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"lynx","version":"2.9.0dev.5-1ubuntu0.1~esm1","description":"classic non-graphical (text-mode) web browser","is_source":true},{"name":"lynx-common","version":"2.9.0dev.5-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"},{"name":"lynx","version":"2.9.0dev.5-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lynx","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-1000211","CVE-2016-9179","CVE-2021-38165"]}]},{"id":"CVE-2017-1000206","published":"2017-11-17T15:29:00","updated_at":"2025-08-25T22:18:30.574492+00:00","description":"\nsamtools htslib library version 1.4.0 and earlier is vulnerable to buffer\noverflow in the CRAM rANS codec resulting in potential arbitrary code\nexecution","ubuntu_description":"\nIt was discovered that HTSlib incorrectly handled certain data. An attacker\ncould possibly use this issue to execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/samtools/htslib/blob/1.4.1/NEWS","https://github.com/samtools/htslib/pull/514","https://www.cve.org/CVERecord?id=CVE-2017-1000206","https://ubuntu.com/security/notices/USN-4802-1"],"bugs":[""],"patches":{"htslib":[]},"tags":{},"packages":[{"name":"htslib","source":"https://ubuntu.com/security/cve?package=htslib","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=htslib","debian":"https://tracker.debian.org/pkg/htslib","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.5-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.2.1-2ubuntu1+esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-4802-1"],"notices":[{"id":"USN-4802-1","title":"HTSlib vulnerabilities","summary":"HTSlib could be made to crash or run programs if it opened a specially\ncrafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2021-03-15T21:29:07.547241","description":"It was discovered that HTSlib incorrectly handled certain data. An attacker\ncould possibly use this issue to execute arbitrary code. This issue affected only Ubuntu\n16.04 ESM. (CVE-2017-1000206)\n\nIt was discovered that HTSlib incorrectly handled certain files. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2018-13845)","is_hidden":false,"release_packages":{"trusty":[{"name":"htslib","version":"0.2.0~rc3-1ubuntu0.1~esm1","description":"C library for high-throughput sequencing data formats","is_source":true},{"name":"libhts-dev","version":"0.2.0~rc3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-infra"},{"name":"htslib-test","version":"0.2.0~rc3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-infra"},{"name":"libhts0","version":"0.2.0~rc3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-infra"}],"bionic":[{"name":"htslib","version":"1.7-2ubuntu0.1~esm1","description":"C library for high-throughput sequencing data formats","is_source":true},{"name":"libhts-dev","version":"1.7-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"tabix","version":"1.7-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"libhts-private-dev","version":"1.7-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"htslib-test","version":"1.7-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"libhts2","version":"1.7-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"htslib","version":"1.2.1-2ubuntu1+esm1","description":"C library for high-throughput sequencing data formats","is_source":true},{"name":"libhts-dev","version":"1.2.1-2ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"libhts1","version":"1.2.1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"htslib-test","version":"1.2.1-2ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"},{"name":"tabix","version":"1.2.1-2ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/htslib","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2018-13845","CVE-2017-1000206"]}]},{"id":"CVE-2017-1000203","published":"2017-11-17T15:29:00","updated_at":"2025-08-25T22:18:30.574492+00:00","description":"\nROOT version 6.9.03 and below is vulnerable to an authenticated shell\nmetacharacter injection in the rootd daemon resulting in remote code\nexecution","ubuntu_description":"\nIt was discovered that ROOT incorrectly certain input arguments. An\nattacker could possibly use this issue to execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/root-project/root/commit/88ccff152604e0f1012653a596d802ff7ede3145#diff-6cd6f6c31bac70116b7ca7abdc8e517e","https://www.cve.org/CVERecord?id=CVE-2017-1000203","https://ubuntu.com/security/notices/USN-4801-1"],"bugs":[""],"patches":{"root-system":[]},"tags":{},"packages":[{"name":"root-system","source":"https://ubuntu.com/security/cve?package=root-system","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=root-system","debian":"https://tracker.debian.org/pkg/root-system","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.34.30-0ubuntu8+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.34.14-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4801-1"],"notices":[{"id":"USN-4801-1","title":"ROOT vulnerability","summary":"ROOT could be made to crash if it received specially crafted\ninput.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T21:26:36.817547","description":"It was discovered that ROOT incorrectly handled certain input arguments. An\nattacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"root-system","version":"5.34.14-1ubuntu0.1~esm1","description":"metapackage to install all ROOT packages","is_source":true},{"name":"libroot-misc-table-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-misc-minicern-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf2d-postscript5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-sql-odbc","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-auth5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-misc-memstat5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-math-minuit2","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-core-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-foam5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-tree-treeplayer-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-core5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-graf2d-asimage","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-hist-spectrumpainter","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-misc-memstat-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-auth-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-montecarlo-eg-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-system-proofd","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-hist-spectrum-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-hist-spectrum5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-mathcore-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-tree-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-montecarlo-pythia8","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-mathmore-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-montecarlo-eg5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-gui-qt","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-mlp5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf3d-gl-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-ldap5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-gui-fitpanel","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-mathcore5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-bonjour-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-tree-treeplayer5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-html-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-net-krb5","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-hist5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-bindings-ruby-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-proof-proofplayer5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-sql-pgsql","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-montecarlo-vmc5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-geom-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-hist-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-genvector-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-mathmore5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-montecarlo-vmc-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-foam-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-physics5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-geom5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-tree-treeviewer","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-io-xmlparser5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-graf3d-x3d","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-physics-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-net-globus","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-minuit5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-smatrix-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-proof-proofplayer-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-ldap-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-io-xml","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-gui-sessionviewer","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf3d-eve-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-system","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-misc-table5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-system-rootd","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-graf2d-qt","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-math-fumili","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-roofit-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-gui5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-geom-gdml","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf3d-eve5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-graf2d-x11","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-system-common","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf2d-graf-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-matrix5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-gui-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-tree5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-geom-geompainter","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-mlp-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-bindings-python-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-hist-histpainter","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"ttf-root-installer","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-roofit5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-gui-ged5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-system-doc","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf2d-postscript-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf3d-g3d5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-gui-guibuilder","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-io-sql","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-quadp5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-tmva5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-genvector5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-bindings-ruby5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-bindings-python5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-gui-ged-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-io-xmlparser-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf2d-gpad5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf3d-gl5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-net-bonjour5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-html5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-unuran5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf2d-gpad-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-sql-mysql","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-matrix-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-smatrix5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-math-fftw3","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf2d-graf5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-unuran-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-static","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-splot5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-hist-hbook","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-splot-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-io-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-misc-minicern5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-proof5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-graf3d-g3d-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-minuit-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-io5.34","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-tmva-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-math-quadp-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-system-bin","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"root-plugin-geom-geombuilder","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"},{"name":"libroot-proof-dev","version":"5.34.14-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"root-system","version":"5.34.30-0ubuntu8+esm1","description":"metapackage to install all ROOT packages","is_source":true},{"name":"libroot-misc-table-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-misc-minicern-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf2d-postscript5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-sql-odbc","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-auth5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-misc-memstat5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-math-minuit2","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-core-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-foam5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-tree-treeplayer-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-core5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-graf2d-asimage","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-hist-spectrumpainter","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-misc-memstat-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-auth-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-montecarlo-eg-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-system-proofd","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-hist-spectrum-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-hist-spectrum5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-mathcore-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-tree-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-montecarlo-pythia8","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-mathmore-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-montecarlo-eg5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-gui-qt","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-mlp5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf3d-gl-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-ldap5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-gui-fitpanel","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-mathcore5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-bonjour-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-tree-treeplayer5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-html-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-net-krb5","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-hist5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-bindings-ruby-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-proof-proofplayer5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-sql-pgsql","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-montecarlo-vmc5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-geom-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-hist-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-genvector-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-mathmore5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-montecarlo-vmc-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-foam-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-physics5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-geom5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-tree-treeviewer","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-io-xmlparser5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-graf3d-x3d","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-physics-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-net-globus","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-minuit5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-smatrix-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-proof-proofplayer-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-ldap-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-io-xml","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-gui-sessionviewer","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf3d-eve-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-system","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-misc-table5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-system-rootd","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-graf2d-qt","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-math-fumili","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-roofit-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-gui5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-geom-gdml","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf3d-eve5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-graf2d-x11","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-system-common","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf2d-graf-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-matrix5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-gui-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-tree5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-geom-geompainter","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-mlp-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-bindings-python-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-hist-histpainter","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"ttf-root-installer","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-roofit5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-gui-ged5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-system-doc","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf2d-postscript-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf3d-g3d5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-gui-guibuilder","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-io-sql","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-quadp5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-tmva5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-genvector5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-bindings-ruby5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-bindings-python5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-gui-ged-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-io-xmlparser-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf2d-gpad5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf3d-gl5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-net-bonjour5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-html5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-unuran5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf2d-gpad-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-sql-mysql","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-matrix-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-smatrix5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-math-fftw3","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf2d-graf5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-unuran-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-static","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-splot5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-hist-hbook","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-splot-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-io-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-misc-minicern5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-proof5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-graf3d-g3d-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-minuit-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-io5.34","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-tmva-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-math-quadp-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-system-bin","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"root-plugin-geom-geombuilder","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"},{"name":"libroot-proof-dev","version":"5.34.30-0ubuntu8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/root-system","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-1000203"]}]},{"id":"CVE-2017-16872","published":"2017-11-17T09:29:00","updated_at":"2026-03-24T22:02:33.459730+00:00","description":"\nAn issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP\nbefore 2.7.1. Parsing the numeric header fields in a SIP message (like\ncseq, ttl, port, etc.) all had the potential to overflow, either causing\nunintended values to be captured or, if the values were subsequently\nconverted back to strings, a buffer overrun. This will lead to a potential\nexploit using carefully crafted invalid values.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://trac.pjsip.org/repos/ticket/2056","https://trac.pjsip.org/repos/changeset/5682","https://trac.pjsip.org/repos/milestone/release-2.7.1","https://www.cve.org/CVERecord?id=CVE-2017-16872","https://ubuntu.com/security/notices/USN-8122-1"],"bugs":[""],"patches":{"pjproject":["upstream: https://github.com/pjsip/pjproject/commit/37f0826f9f89e2255332afa1ffa5d72dab4a149d"]},"tags":{},"packages":[{"name":"pjproject","source":"https://ubuntu.com/security/cve?package=pjproject","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pjproject","debian":"https://tracker.debian.org/pkg/pjproject","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.7.2~dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.1~dfsg-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-8122-1"],"notices":[{"id":"USN-8122-1","title":"PJSIP vulnerabilities","summary":"Several security issues were fixed in PJSIP.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-24T20:34:47.281461","description":"Youngsung Kim discovered that PJSIP did not properly parse numeric header\nfields in SIP messages. A remote attacker could use this issue to cause\nPJSIP to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-16872)\n\nPeter Koletzki discovered that PJSIP did not properly handle certain\nconnection requests. A remote attacker could possibly use this issue to\ncause PJSIP to enter an unrecoverable state and reject further connections,\nresulting in a denial of service. This issue only affected Ubuntu 16.04\nLTS. (CVE-2017-16875)\n\nAlfred Farrugia, Sandro Gauci, and Kevin Harwell discovered that PJSIP did\nnot properly parse certain SDP messages. A remote attacker could possibly\nuse this issue to cause PJSIP to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2018-1000098,\nCVE-2018-1000099)\n\nLauri Vänskä discovered that PJSIP did not verify hostnames when reusing\nTLS connections. If a remote attacker were able to intercept communication,\nthis flaw could possibly be exploited to view sensitive information.\n(CVE-2020-15260)\n\nIt was discovered that PJSIP did not properly handle certain sequences of\nSDP messages. A remote attacker could possibly use this issue to cause\nPJSIP to crash, resulting in a denial of service. (CVE-2021-21375)\n\nIt was discovered that the SSL socket implementation in PJSIP contained a\nrace condition. A remote attacker could possibly use this issue to cause\nPJSIP to crash, resulting in a denial of service. This issue was only\naddressed in Ubuntu 18.04 LTS. (CVE-2021-32686)\n\nIt was discovered that PJSIP did not properly parse certain STUN messages.\nA remote attacker could use this issue to cause PJSIP to crash, resulting\nin a denial of service, or possibly execute arbitrary code.\n(CVE-2021-37706)\n\nUriya Yavnieli discovered that PJSIP did not properly manage memory under\ncertain conditions. A remote attacker could use this issue to cause PJSIP\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2021-43299, CVE-2021-43300, CVE-2021-43301, CVE-2021-43302,\nCVE-2021-43303)\n\nIt was discovered that PJSIP did not properly manage memory when processing\nICE session credentials. A remote attacker could use this issue to cause\nPJSIP to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2026-25994)","is_hidden":false,"release_packages":{"bionic":[{"name":"pjproject","version":"2.7.2~dfsg-1ubuntu0.1~esm1","description":"multimedia communication library","is_source":true},{"name":"libpj2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjlib-util2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-audiodev2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-codec2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-videodev2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjnath2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjproject-dev","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-simple2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-ua2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsua2","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsua2-2v5","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"python-pjproject","version":"2.7.2~dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"pjproject","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","description":"multimedia communication library","is_source":true},{"name":"libpj2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjlib-util2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-audiodev2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-codec2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia-videodev2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjmedia2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjnath2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjproject-dev","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-simple2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip-ua2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsip2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"},{"name":"libpjsua2","version":"2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pjproject","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-15260","CVE-2021-43300","CVE-2026-25994","CVE-2017-16872","CVE-2018-1000099","CVE-2021-37706","CVE-2021-43302","CVE-2021-43301","CVE-2018-1000098","CVE-2021-43303","CVE-2021-32686","CVE-2017-16875","CVE-2021-21375","CVE-2021-43299"]}]},{"id":"CVE-2017-16869","published":"2017-11-17T09:29:00","updated_at":"2025-08-04T19:24:58.608691+00:00","description":"\np_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service\n(invalid memory access and application crash) or possibly have unspecified\nother impact via a crafted Mach-O file, related to canPack and unpack\nfunctions. NOTE: the vendor has stated \"there is no security implication\nwhatsoever.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/upx/upx/issues/146","https://www.cve.org/CVERecord?id=CVE-2017-16869"],"bugs":[""],"patches":{"upx-ucl":[]},"tags":{},"packages":[{"name":"upx-ucl","source":"https://ubuntu.com/security/cve?package=upx-ucl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=upx-ucl","debian":"https://tracker.debian.org/pkg/upx-ucl","statuses":[{"release_codename":"impish","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.94-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16868","published":"2017-11-17T09:29:00","updated_at":"2025-08-26T11:59:11.689219+00:00","description":"\nIn SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not\nproperly restrict a multiplication within a malloc call, which allows\nremote attackers to cause a denial of service (integer overflow and NULL\npointer dereference) via a crafted WAV file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/52","https://www.cve.org/CVERecord?id=CVE-2017-16868"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000248","published":"2017-11-17T04:29:00","updated_at":"2025-07-17T16:42:52.514323+00:00","description":"\nRedis-store <=v1.3.0 allows unsafe objects to be loaded from redis","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/redis-store/redis-store/commit/e0c1398d54a9661c8c70267c3a925ba6b192142e","https://www.cve.org/CVERecord?id=CVE-2017-1000248"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882034"],"patches":{"ruby-redis-store":[]},"tags":{},"packages":[{"name":"ruby-redis-store","source":"https://ubuntu.com/security/cve?package=ruby-redis-store","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-redis-store","debian":"https://tracker.debian.org/pkg/ruby-redis-store","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.0-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.0-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.6-1+deb9u1, 1.1.6-2, 1.3.0-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.1.6-1+deb9u1build0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000246","published":"2017-11-17T04:29:00","updated_at":"2025-08-26T11:57:01.649700+00:00","description":"\nPython package pysaml2 version 4.4.0 and earlier reuses the initialization\nvector across encryptions in the IDP server, resulting in weak encryption\nof data.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"The discussion in the GitHub issue explains why this isn't currently\nan issue but could be in the future if new cipher modes are used."}],"codename":null,"priority":"negligible","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/rohe/pysaml2/issues/417","https://www.cve.org/CVERecord?id=CVE-2017-1000246"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882012"],"patches":{"python-pysaml2":[]},"tags":{},"packages":[{"name":"python-pysaml2","source":"https://ubuntu.com/security/cve?package=python-pysaml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pysaml2","debian":"https://tracker.debian.org/pkg/python-pysaml2","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.0-f","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.5.0+dfsg1-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":54560,"limit":20,"total_results":79316}