{"cves":[{"id":"CVE-2017-1000189","published":"2017-11-17T03:29:00","updated_at":"2025-08-25T22:18:25.478107+00:00","description":"\nnodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service\ndue to weak input validation in the ejs.renderFile()","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f (v2.5.4)","https://www.cve.org/CVERecord?id=CVE-2017-1000189"],"bugs":[""],"patches":{"node-ejs":[]},"tags":{},"packages":[{"name":"node-ejs","source":"https://ubuntu.com/security/cve?package=node-ejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-ejs","debian":"https://tracker.debian.org/pkg/node-ejs","statuses":[{"release_codename":"bionic","status":"not-affected","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.7-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000188","published":"2017-11-17T03:29:00","updated_at":"2025-08-25T22:18:25.478107+00:00","description":"\nnodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting\nin the ejs.renderFile() resulting in code injection","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f (v2.5.4)","https://www.cve.org/CVERecord?id=CVE-2017-1000188"],"bugs":[""],"patches":{"node-ejs":["upstream: https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f"]},"tags":{},"packages":[{"name":"node-ejs","source":"https://ubuntu.com/security/cve?package=node-ejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-ejs","debian":"https://tracker.debian.org/pkg/node-ejs","statuses":[{"release_codename":"bionic","status":"not-affected","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.1.6-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.1.8+~3.1.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.7-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000187","published":"2017-11-17T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nIn SWFTools, an address access exception was found in pdf2swf.\nFoFiTrueType::writeTTF()","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/36","https://www.cve.org/CVERecord?id=CVE-2017-1000187"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000186","published":"2017-11-17T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nIn SWFTools, a stack overflow was found in pdf2swf.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/34","https://www.cve.org/CVERecord?id=CVE-2017-1000186"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000185","published":"2017-11-17T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nIn SWFTools, a memcpy buffer overflow was found in gif2swf.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/33","https://www.cve.org/CVERecord?id=CVE-2017-1000185"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000182","published":"2017-11-17T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nIn SWFTools, a memory leak was found in wav2swf.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/30","https://www.cve.org/CVERecord?id=CVE-2017-1000182"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000176","published":"2017-11-17T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nIn SWFTools, a memcpy buffer overflow was found in swfc.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/23","https://www.cve.org/CVERecord?id=CVE-2017-1000176"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000174","published":"2017-11-17T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nIn SWFTools, an address access exception was found in swfdump\nswf_GetBits().","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/matthiaskramm/swftools/issues/21","https://www.cve.org/CVERecord?id=CVE-2017-1000174"],"bugs":[""],"patches":{"swftools":[]},"tags":{},"packages":[{"name":"swftools","source":"https://ubuntu.com/security/cve?package=swftools","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=swftools","debian":"https://tracker.debian.org/pkg/swftools","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16845","published":"2017-11-17T00:00:00","updated_at":"2025-08-25T22:28:03.693605+00:00","description":"\nhw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during\nguest migration, leading to out-of-bounds access.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"trusty has a fixed-size queue, doesn't look like an issue."}],"codename":null,"priority":"low","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/qemu-devel/2017-11/msg02982.html","https://ubuntu.com/security/notices/USN-3575-1","https://ubuntu.com/security/notices/USN-3649-1","https://www.cve.org/CVERecord?id=CVE-2017-16845"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882136"],"patches":{"qemu-kvm":[],"qemu":["upstream: https://git.qemu.org/?p=qemu.git;a=commitdiff;h=802cbcb73002b92e6ddc8464d39b668a71b78d74"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"artful","status":"released","description":"1:2.10+dfsg-0ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.11+dfsg-1ubuntu7.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.22","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3575-1","USN-3649-1"],"notices":[{"id":"USN-3575-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2018-02-20T19:12:03.197057","description":"It was discovered that QEMU incorrectly handled guest ram. A privileged\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2017-11334)\n\nDavid Buchanan discovered that QEMU incorrectly handled the VGA device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue was only addressed in\nUbuntu 17.10. (CVE-2017-13672)\n\nThomas Garnier discovered that QEMU incorrectly handled multiboot. An\nattacker could use this issue to cause QEMU to crash, resulting in a denial\nof service, or possibly execute arbitrary code on the host. In the default\ninstallation, when QEMU is used with libvirt, attackers would be isolated\nby the libvirt AppArmor profile. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2017-14167)\n\nTuomas Tynkkynen discovered that QEMU incorrectly handled VirtFS directory\nsharing. An attacker could use this issue to obtain sensitive information\nfrom host memory. (CVE-2017-15038)\n\nEric Blake discovered that QEMU incorrectly handled memory in the\nNBD server. An attacker could use this issue to cause the NBD server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n17.10. (CVE-2017-15118)\n\nEric Blake discovered that QEMU incorrectly handled certain options to the\nNBD server. An attacker could use this issue to cause the NBD server to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-15119)\n\nDaniel Berrange discovered that QEMU incorrectly handled the VNC server. A\nremote attacker could possibly use this issue to consume memory, resulting\nin a denial of service. This issue was only addressed in Ubuntu 17.10.\n(CVE-2017-15124)\n\nCarl Brassey discovered that QEMU incorrectly handled certain websockets. A\nremote attacker could possibly use this issue to consume memory, resulting\nin a denial of service. This issue only affected Ubuntu 17.10.\n(CVE-2017-15268)\n\nGuoxiang Niu discovered that QEMU incorrectly handled the Cirrus VGA\ndevice. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2017-15289)\n\nCyrille Chatras discovered that QEMU incorrectly handled certain PS2 values\nduring migration. An attacker could possibly use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 16.04 LTS and Ubuntu 17.10.\n(CVE-2017-16845)\n\nIt was discovered that QEMU incorrectly handled the Virtio Vring\nimplementation. An attacker could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 17.10. (CVE-2017-17381)\n\nEric Blake discovered that QEMU incorrectly handled certain rounding\noperations. An attacker could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-18043)\n\nJiang Xin and Lin ZheCheng discovered that QEMU incorrectly handled the\nVGA device. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2018-5683)\n","is_hidden":false,"release_packages":{"artful":[{"name":"qemu","version":"1:2.10+dfsg-0ubuntu3.5","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-aarch64","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-arm","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-mips","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-misc","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-ppc","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-s390x","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-sparc","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"},{"name":"qemu-system-x86","version":"1:2.10+dfsg-0ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.5"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.39","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.39","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.22","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.22","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-11334","CVE-2017-13672","CVE-2017-14167","CVE-2017-15038","CVE-2017-15118","CVE-2017-15119","CVE-2017-15124","CVE-2017-15268","CVE-2017-15289","CVE-2017-16845","CVE-2017-17381","CVE-2017-18043","CVE-2018-5683"]},{"id":"USN-3649-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2018-05-16T12:03:54.459199","description":"Cyrille Chatras discovered that QEMU incorrectly handled certain PS2 values\nduring migration. An attacker could possibly use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 18.04 LTS. (CVE-2017-16845)\n\nCyrille Chatras discovered that QEMU incorrectly handled multiboot. An\nattacker could use this issue to cause QEMU to crash, resulting in a denial\nof service, or possibly execute arbitrary code on the host. In the default\ninstallation, when QEMU is used with libvirt, attackers would be isolated\nby the libvirt AppArmor profile. (CVE-2018-7550)\n\nRoss Lagerwall discovered that QEMU incorrectly handled the Cirrus VGA\ndevice. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 17.10 and Ubuntu 18.04 LTS. (CVE-2018-7858)\n","is_hidden":false,"release_packages":{"artful":[{"name":"qemu","version":"1:2.10+dfsg-0ubuntu3.6","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-aarch64","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-arm","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-mips","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-ppc","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-s390x","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-sparc","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"},{"name":"qemu-system-x86","version":"1:2.10+dfsg-0ubuntu3.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.10+dfsg-0ubuntu3.6"}],"bionic":[{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-kvm","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-common","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-user","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-user-static","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"},{"name":"qemu-utils","version":"1:2.11+dfsg-1ubuntu7.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.1","pocket":"security"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.41","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.41","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.41","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.28","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.28","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.28","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-16845","CVE-2018-7550","CVE-2018-7858"]}]},{"id":"CVE-2017-1000229","published":"2017-11-17T00:00:00","updated_at":"2025-08-25T22:18:30.574492+00:00","description":"\nInteger overflow bug in function minitiff_read_info() of optipng 0.7.6\nallows an attacker to remotely execute code or cause denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3495-1","https://www.cve.org/CVERecord?id=CVE-2017-1000229"],"bugs":["https://sourceforge.net/p/optipng/bugs/65/","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=882032"],"patches":{"optipng":["other: https://sourceforge.net/p/optipng/bugs/65/#f6bb"]},"tags":{},"packages":[{"name":"optipng","source":"https://ubuntu.com/security/cve?package=optipng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=optipng","debian":"https://tracker.debian.org/pkg/optipng","statuses":[{"release_codename":"artful","status":"released","description":"0.7.6-1ubuntu0.17.10.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.6.4-1ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.7.6-1ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.7.6-1ubuntu0.17.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3495-1"],"notices":[{"id":"USN-3495-1","title":"OptiPNG vulnerability","summary":"OptiPNG could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-11-27T17:53:14.686484","description":"It was discovered that OptiPNG incorrectly handled memory. A remote\nattacker could use this issue with a specially crafted image file to cause\nOptiPNG to crash, resulting in a denial of service, or possibly execute\narbitrary code.\n","is_hidden":false,"release_packages":{"artful":[{"name":"optipng","version":"0.7.6-1ubuntu0.17.10.1","description":"advanced PNG (Portable Network Graphics) optimizer","is_source":true},{"name":"optipng","version":"0.7.6-1ubuntu0.17.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/optipng","version_link":"https://launchpad.net/ubuntu/+source/optipng/0.7.6-1ubuntu0.17.10.1"}],"trusty":[{"name":"optipng","version":"0.6.4-1ubuntu0.14.04.2","description":"advanced PNG (Portable Network Graphics) optimizer","is_source":true},{"name":"optipng","version":"0.6.4-1ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/optipng","version_link":"https://launchpad.net/ubuntu/+source/optipng/0.6.4-1ubuntu0.14.04.2","pocket":"security"}],"xenial":[{"name":"optipng","version":"0.7.6-1ubuntu0.16.04.1","description":"advanced PNG (Portable Network Graphics) optimizer","is_source":true},{"name":"optipng","version":"0.7.6-1ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/optipng","version_link":"https://launchpad.net/ubuntu/+source/optipng/0.7.6-1ubuntu0.16.04.1","pocket":"security"}],"zesty":[{"name":"optipng","version":"0.7.6-1ubuntu0.17.04.1","description":"advanced PNG (Portable Network Graphics) optimizer","is_source":true},{"name":"optipng","version":"0.7.6-1ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/optipng","version_link":"https://launchpad.net/ubuntu/+source/optipng/0.7.6-1ubuntu0.17.04.1"}]},"type":"USN","cves_ids":["CVE-2017-1000229"]}]},{"id":"CVE-2017-1000158","published":"2017-11-17T00:00:00","updated_at":"2025-08-25T22:18:25.478107+00:00","description":"\nCPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in\nthe PyString_DecodeEscape function in stringobject.c, resulting in\nheap-based buffer overflow (and possible arbitrary code execution)","ubuntu_description":"","notes":[{"author":"tyhicks","note":"PyBytes_DecodeEscape() may be affected in Python 3.x versions. Please\ncheck."},{"author":"mdeslaur","note":"per upstream bug, 3.6 and 3.7 aren't affected"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/python/cpython/commit/c3c9db89273fabc62ea1b48389d9a3000c1c03ae","https://ubuntu.com/security/notices/USN-3496-1","https://ubuntu.com/security/notices/USN-3496-2","https://ubuntu.com/security/notices/USN-3496-3","https://www.cve.org/CVERecord?id=CVE-2017-1000158"],"bugs":["https://bugs.python.org/issue30657"],"patches":{"python2.7":[],"python3.4":[],"python3.5":[],"python3.6":[],"python3.7":[]},"tags":{},"packages":[{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.7.14-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.7.6-8ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.13-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.7.12-1ubuntu0~16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.7.13-2ubuntu0.1","component":null,"pocket":"security"}]},{"name":"python3.4","source":"https://ubuntu.com/security/cve?package=python3.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.4","debian":"https://tracker.debian.org/pkg/python3.4","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.4.3-1ubuntu1~14.04.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.5","source":"https://ubuntu.com/security/cve?package=python3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.5","debian":"https://tracker.debian.org/pkg/python3.5","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.5.2-2ubuntu0~16.04.4~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.5.2-2ubuntu0~16.04.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"3.5.3-1ubuntu0~17.04.2","component":null,"pocket":"security"}]},{"name":"python3.6","source":"https://ubuntu.com/security/cve?package=python3.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.6","debian":"https://tracker.debian.org/pkg/python3.6","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"python3.7","source":"https://ubuntu.com/security/cve?package=python3.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.7","debian":"https://tracker.debian.org/pkg/python3.7","statuses":[{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3496-1","USN-3496-3","USN-3496-2"],"notices":[{"id":"USN-3496-1","title":"Python vulnerability","summary":"Python could be made to run arbitrary code.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-11-28T15:34:12.898193","description":"It was discovered that Python incorrectly handled decoding certain strings.\nAn attacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"python2.7","version":"2.7.6-8ubuntu0.4","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python2.7","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"libpython2.7","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"libpython2.7-dev","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"libpython2.7-minimal","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"libpython2.7-stdlib","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"libpython2.7-testsuite","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"python2.7","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"python2.7-dev","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"python2.7-doc","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"python2.7-examples","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"},{"name":"python2.7-minimal","version":"2.7.6-8ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.6-8ubuntu0.4","pocket":"security"}],"xenial":[{"name":"python2.7","version":"2.7.12-1ubuntu0~16.04.2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python2.7","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"libpython2.7","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"libpython2.7-dev","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"libpython2.7-minimal","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"libpython2.7-stdlib","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"libpython2.7-testsuite","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"python2.7","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"python2.7-dev","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"python2.7-doc","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"python2.7-examples","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"},{"name":"python2.7-minimal","version":"2.7.12-1ubuntu0~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.2","pocket":"security"}],"zesty":[{"name":"python2.7","version":"2.7.13-2ubuntu0.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.7","version":"2.7.13-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.13-2ubuntu0.1"},{"name":"python2.7-minimal","version":"2.7.13-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.13-2ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-1000158"]},{"id":"USN-3496-3","title":"Python vulnerability","summary":"Python could be made to run arbitrary code.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-11-28T19:37:35.092180","description":"USN-3496-1 fixed a vulnerability in Python2.7. This update provides\nthe corresponding update for versions 3.4 and 3.5.\n\nOriginal advisory details:\n\n It was discovered that Python incorrectly handled decoding certain strings.\n An attacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"python3.4","version":"3.4.3-1ubuntu1~14.04.6","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.4","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"libpython3.4","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"libpython3.4-dev","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"libpython3.4-minimal","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"libpython3.4-stdlib","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"libpython3.4-testsuite","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"python3.4","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"python3.4-dev","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"python3.4-doc","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"python3.4-examples","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"python3.4-minimal","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"},{"name":"python3.4-venv","version":"3.4.3-1ubuntu1~14.04.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.4","version_link":"https://launchpad.net/ubuntu/+source/python3.4/3.4.3-1ubuntu1~14.04.6","pocket":"security"}],"xenial":[{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.4","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.5","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"libpython3.5","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"libpython3.5-dev","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"libpython3.5-minimal","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"libpython3.5-stdlib","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"libpython3.5-testsuite","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"python3.5","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"python3.5-dev","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"python3.5-doc","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"python3.5-examples","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"python3.5-minimal","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"},{"name":"python3.5-venv","version":"3.5.2-2ubuntu0~16.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.2-2ubuntu0~16.04.4","pocket":"security"}],"zesty":[{"name":"python3.5","version":"3.5.3-1ubuntu0~17.04.2","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python3.5","version":"3.5.3-1ubuntu0~17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.3-1ubuntu0~17.04.2"},{"name":"python3.5-minimal","version":"3.5.3-1ubuntu0~17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.5","version_link":"https://launchpad.net/ubuntu/+source/python3.5/3.5.3-1ubuntu0~17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-1000158"]},{"id":"USN-3496-2","title":"Python vulnerability","summary":"Python could be made to run arbitrary code.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-11-28T16:57:04.978262","description":"USN-3496-1 fixed a vulnerability in Python. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Python incorrectly handled decoding certain strings.\n An attacker could possibly use this issue to execute arbitrary code.\n","is_hidden":false,"release_packages":{"precise":[{"name":"python2.7","version":"2.7.3-0ubuntu3.10","description":"An interactive high-level object-oriented language","is_source":true},{"name":"python2.7-minimal","version":"2.7.3-0ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.3-0ubuntu3.10"},{"name":"python2.7","version":"2.7.3-0ubuntu3.10","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/python2.7","version_link":"https://launchpad.net/ubuntu/+source/python2.7/2.7.3-0ubuntu3.10"}]},"type":"USN","cves_ids":["CVE-2017-1000158"]}]},{"id":"CVE-2017-0863","published":"2017-11-16T23:29:00","updated_at":"2025-08-25T22:17:58.521828+00:00","description":"\nAn elevation of privilege vulnerability in the Upstream kernel video\ndriver. Product: Android. Versions: Android kernel. Android ID: A-37950620.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"There's currently not much info available on this but the CVE\ndescription makes it sound like it affects the upstream kernel."},{"author":"sbeattie","note":"affected the \"ASUS IT8566 HDMI CEC driver\"; i.e.\ndrivers/video/it8566_hdmi_cec/it8566_hdmi_cec.c"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0863"],"bugs":[""],"patches":{"linux":["break-fix: - -"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[]},"tags":{"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needs-triage]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel/driver only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0862","published":"2017-11-16T23:29:00","updated_at":"2025-08-25T22:17:58.521828+00:00","description":"\nAn elevation of privilege vulnerability in the Upstream kernel kernel.\nProduct: Android. Versions: Android kernel. Android ID: A-36006779.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"There's currently not much info available on this but the CVE\ndescription makes it sound like it affects the upstream kernel."},{"author":"sbeattie","note":"in drivers/input/misc/keychord.c::keychord_write()\ncode does not exist in upstream kernel."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://github.com/LineageOS/android_kernel_huawei_angler/commit/3fa9d0a94130e8d5b2e3520c58f549664f4c8353","https://www.cve.org/CVERecord?id=CVE-2017-0862"],"bugs":[""],"patches":{"linux":["break-fix: - -"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[]},"tags":{"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"trusty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [android kernel only]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"upstream","status":"not-affected","description":"android kernel only","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0860","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nAn elevation of privilege vulnerability in the Android system\n(inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1,\n7.0, 7.1.1, 7.1.2. Android ID: A-31097064.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0860"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0859","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nAnother vulnerability in the Android media framework (n/a). Product:\nAndroid. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36075131.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0859"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0858","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nAnother vulnerability in the Android media framework (n/a). Product:\nAndroid. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0858"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0857","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nAnother vulnerability in the Android media framework (n/a). Product:\nAndroid. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-65122447.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0857"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0854","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nAn information disclosure vulnerability in the Android media framework\n(n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID:\nA-63873837.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0854"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0853","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nAn information disclosure vulnerability in the Android media framework\n(n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID:\nA-63121644.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0853"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0852","published":"2017-11-16T23:29:00","updated_at":"2025-07-17T16:42:50.814804+00:00","description":"\nA denial of service vulnerability in the Android media framework (libhevc).\nProduct: Android. Versions: 5.0.2, 5.1.1, 6.0. Android ID: A-62815506.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"Ubuntu's android package is the emulator."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://source.android.com/security/bulletin/pixel/2017-11-01","https://www.cve.org/CVERecord?id=CVE-2017-0852"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":54580,"limit":20,"total_results":79316}