{"cves":[{"id":"CVE-2017-16352","published":"2017-11-01T15:29:00","updated_at":"2025-08-25T22:27:35.459155+00:00","description":"\nGraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow\nvulnerability found in the \"Display visual image directory\" feature of the\nDescribeImage() function of the magick/describe.c file. One possible way to\ntrigger the vulnerability is to run the identify command on a specially\ncrafted MIFF format file with the verbose flag.","ubuntu_description":"\nIt was discovered that GraphicsMagick incorrectly handled certain image\nfiles. An attacker could possibly use this issue to cause a denial of\nservice or other unspecified impact.","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=7292230dd185","https://blogs.securiteam.com/index.php/archives/3494","https://ubuntu.com/security/notices/USN-4232-1","https://www.cve.org/CVERecord?id=CVE-2017-16352"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.18-1ubuntu3.1+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.23-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.3.26-17","component":null,"pocket":"security"}]}],"notices_ids":["USN-4232-1"],"notices":[{"id":"USN-4232-1","title":"GraphicsMagick vulnerabilities","summary":"Several security issues were fixed in GraphicsMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-01-08T17:42:19.392930","description":"It was discovered that GraphicsMagick incorrectly handled certain image files.\nAn attacker could possibly use this issue to cause a denial of service or other\nunspecified impact.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"graphicsmagick","version":"1.3.23-1ubuntu0.4","description":"collection of image processing tools","is_source":true},{"name":"graphicsmagick","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"graphicsmagick-imagemagick-compat","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"graphicsmagick-libmagick-dev-compat","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphics-magick-perl","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick++-q16-12","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick++1-dev","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick-q16-3","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick1-dev","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14165","CVE-2017-14314","CVE-2017-14504","CVE-2017-14649","CVE-2017-14733","CVE-2017-14994","CVE-2017-14997","CVE-2017-15277","CVE-2017-15930","CVE-2017-16352","CVE-2017-16353"]}]},{"id":"CVE-2017-16248","published":"2017-11-01T01:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nThe Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote\nattackers to read arbitrary files if there is a '.' character anywhere in\nthe pathname, which differs from the intended policy of allowing access\nonly when the filename itself has a '.' character.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://rt.cpan.org/Public/Bug/Display.html?id=120558","https://bugs.debian.org/880458","https://metacpan.org/changes/distribution/Catalyst-Plugin-Static-Simple","https://www.cve.org/CVERecord?id=CVE-2017-16248"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=880458"],"patches":{"libcatalyst-plugin-static-simple-perl":[]},"tags":{},"packages":[{"name":"libcatalyst-plugin-static-simple-perl","source":"https://ubuntu.com/security/cve?package=libcatalyst-plugin-static-simple-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcatalyst-plugin-static-simple-perl","debian":"https://tracker.debian.org/pkg/libcatalyst-plugin-static-simple-perl","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.34-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15535","published":"2017-11-01T01:29:00","updated_at":"2025-07-17T16:42:57.217380+00:00","description":"\nMongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a\ndisabled-by-default configuration setting, networkMessageCompressors (aka\nwire protocol compression), which exposes a vulnerability when enabled that\ncould be exploited by a malicious attacker to deny service or modify\nmemory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://jira.mongodb.org/browse/SERVER-31273","https://www.cve.org/CVERecord?id=CVE-2017-15535"],"bugs":[""],"patches":{"mongodb":[]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:3.6.3-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:3.4.15-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12608","published":"2017-11-01T00:00:00","updated_at":"2025-08-25T22:22:15.891964+00:00","description":"\nA vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4,\nand specifically in ImportOldFormatStyles, allows attackers to craft\nmalicious documents that cause denial of service (memory corruption and\napplication crash) potentially resulting in arbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.talosintelligence.com/reports/TALOS-2017-0301","https://www.libreoffice.org/about-us/security/advisories/CVE-2017-12608","https://ubuntu.com/security/notices/USN-3472-1","https://www.cve.org/CVERecord?id=CVE-2017-12608"],"bugs":[""],"patches":{"libreoffice":["upstream: https://cgit.freedesktop.org/libreoffice/core/commit/?id=42a709d1ef647aab9a1c9422b4e25ecaee857aba"]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:5.4.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.8-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.2,5.1.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:5.1.6~rc2-0ubuntu1~xenial2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:5.3.1-0ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3472-1"],"notices":[{"id":"USN-3472-1","title":"LibreOffice vulnerabilities","summary":"LibreOffice could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"After a standard system update you need to restart LibreOffice to make all\nthe necessary changes.\n","references":[],"published":"2017-11-02T12:45:40.983525","description":"Marcin Noga discovered that LibreOffice incorrectly handled PPT documents.\nIf a user were tricked into opening a specially crafted PPT document, a\nremote attacker could cause LibreOffice to crash, and possibly execute\narbitrary code. (CVE-2017-12607)\n\nMarcin Noga discovered that LibreOffice incorrectly handled Word documents.\nIf a user were tricked into opening a specially crafted Word document, a\nremote attacker could cause LibreOffice to crash, and possibly execute\narbitrary code. (CVE-2017-12608)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libreoffice","version":"1:4.2.8-0ubuntu5.2","description":"Office productivity suite","is_source":true},{"name":"browser-plugin-libreoffice","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"fonts-opensymbol","version":"2:102.6+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-avmedia-backend-gstreamer","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-base","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-base-core","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-base-drivers","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-calc","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-common","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-core","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-dev","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-dev-doc","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-draw","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-emailmerge","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-gnome","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-gtk","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-gtk3","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-impress","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-java-common","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-kde","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-l10n-in","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-l10n-ku","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-l10n-za","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-librelogo","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-math","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-mysql-connector","version":"1.0.2+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-officebean","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-ogltrans","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-pdfimport","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-presentation-minimizer","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-presenter-console","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-report-builder","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-report-builder-bin","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-script-provider-bsh","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-script-provider-js","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-script-provider-python","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-sdbc-firebird","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-sdbc-hsqldb","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-sdbc-postgresql","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-crystal","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-galaxy","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-hicontrast","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-human","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-oxygen","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-sifr","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-tango","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-subsequentcheckbase","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-wiki-publisher","version":"1.1.2+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-writer","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"openoffice.org-dtd-officedocument1.0","version":"2:1.0+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"python3-uno","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"uno-libs3","version":"4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"ure","version":"4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12607","CVE-2017-12608"]}]},{"id":"CVE-2017-12607","published":"2017-11-01T00:00:00","updated_at":"2025-08-25T22:22:15.891964+00:00","description":"\nA vulnerability in OpenOffice's PPT file parser before 4.1.4, and\nspecifically in PPTStyleSheet, allows attackers to craft malicious\ndocuments that cause denial of service (memory corruption and application\ncrash) potentially resulting in arbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.talosintelligence.com/reports/TALOS-2017-0300","https://www.libreoffice.org/about-us/security/advisories/CVE-2017-12607","https://ubuntu.com/security/notices/USN-3472-1","https://www.cve.org/CVERecord?id=CVE-2017-12607"],"bugs":[""],"patches":{"libreoffice":["upstream: https://cgit.freedesktop.org/libreoffice/core/commit/?id=334dba623dfb0c4fb2b5292c2d03741b7b33aef1"]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:5.4.1-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.0.2,5.4.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1:5.1.6~rc2-0ubuntu1~xenial2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:5.3.1-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:4.2.8-0ubuntu5.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3472-1"],"notices":[{"id":"USN-3472-1","title":"LibreOffice vulnerabilities","summary":"LibreOffice could be made to crash or run programs as your login if it\nopened a specially crafted file.\n","instructions":"After a standard system update you need to restart LibreOffice to make all\nthe necessary changes.\n","references":[],"published":"2017-11-02T12:45:40.983525","description":"Marcin Noga discovered that LibreOffice incorrectly handled PPT documents.\nIf a user were tricked into opening a specially crafted PPT document, a\nremote attacker could cause LibreOffice to crash, and possibly execute\narbitrary code. (CVE-2017-12607)\n\nMarcin Noga discovered that LibreOffice incorrectly handled Word documents.\nIf a user were tricked into opening a specially crafted Word document, a\nremote attacker could cause LibreOffice to crash, and possibly execute\narbitrary code. (CVE-2017-12608)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libreoffice","version":"1:4.2.8-0ubuntu5.2","description":"Office productivity suite","is_source":true},{"name":"browser-plugin-libreoffice","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"fonts-opensymbol","version":"2:102.6+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-avmedia-backend-gstreamer","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-base","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-base-core","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-base-drivers","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-calc","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-common","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-core","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-dev","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-dev-doc","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-draw","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-emailmerge","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-gnome","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-gtk","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-gtk3","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-impress","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-java-common","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-kde","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-l10n-in","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-l10n-ku","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-l10n-za","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-librelogo","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-math","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-mysql-connector","version":"1.0.2+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-officebean","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-ogltrans","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-pdfimport","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-presentation-minimizer","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-presenter-console","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-report-builder","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-report-builder-bin","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-script-provider-bsh","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-script-provider-js","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-script-provider-python","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-sdbc-firebird","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-sdbc-hsqldb","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-sdbc-postgresql","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-crystal","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-galaxy","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-hicontrast","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-human","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-oxygen","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-sifr","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-style-tango","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-subsequentcheckbase","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-wiki-publisher","version":"1.1.2+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"libreoffice-writer","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"openoffice.org-dtd-officedocument1.0","version":"2:1.0+LibO4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"python3-uno","version":"1:4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"uno-libs3","version":"4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"},{"name":"ure","version":"4.2.8-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libreoffice","version_link":"https://launchpad.net/ubuntu/+source/libreoffice/1:4.2.8-0ubuntu5.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12607","CVE-2017-12608"]}]},{"id":"CVE-2017-1000383","published":"2017-10-31T20:29:00","updated_at":"2025-08-25T22:18:45.135949+00:00","description":"\nGNU Emacs version 25.3.1 (and other versions most likely) ignores umask\nwhen creating a backup save file (\"[ORIGINAL_FILENAME]~\") resulting in\nfiles that may be world readable or otherwise accessible in ways not\nintended by the user running the emacs binary.","ubuntu_description":"","notes":[{"author":"leosilva","note":"It really seems to not be a vulnerability. See all the comments\naround this issue in emacs. I'll set it as ignored."}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/10/31/15","http://www.openwall.com/lists/oss-security/2017/10/31/1","https://www.cve.org/CVERecord?id=CVE-2017-1000383"],"bugs":[""],"patches":{"emacs24":[],"emacs25":[],"emacs23":[]},"tags":{},"packages":[{"name":"emacs23","source":"https://ubuntu.com/security/cve?package=emacs23","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs23","debian":"https://tracker.debian.org/pkg/emacs23","statuses":[{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"emacs24","source":"https://ubuntu.com/security/cve?package=emacs24","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs24","debian":"https://tracker.debian.org/pkg/emacs24","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"emacs25","source":"https://ubuntu.com/security/cve?package=emacs25","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=emacs25","debian":"https://tracker.debian.org/pkg/emacs25","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000382","published":"2017-10-31T20:29:00","updated_at":"2026-08-06T19:11:05.350009+00:00","description":"\nVIM version 8.0.1187 (and other versions most likely) ignores umask when\ncreating a swap file (\"[ORIGINAL_FILENAME].swp\") resulting in files that\nmay be world readable or otherwise accessible in ways not intended by the\nuser running the vi binary.","ubuntu_description":"","notes":[{"author":"leosilva","note":"I could reproduce following openwall steps\nafter apply the patch community put available\nand repeat the steps in openwall I still got\nthe same bug behaviour so not sure if patch fix it waiting any comment from community\nI could confirm with upstream the patch debian put available from upstream doesn't fix the issue"},{"author":"msalvatore","note":"Bram Moolenar (vim's BDFL) had this to say:\n1) The permissions are the same as the original file, and that is exactly how it should be.\n2) This is working as intended, Vim does not use umask this way. Umask is only used by\nsimple commands such as cp, not by long running processes that deal with many files.\nProblem is with the user expectations."},{"author":"mdeslaur","note":"This issue has been disputed by vim developers, marking as\nnot-affected."}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/10/31/15","http://www.openwall.com/lists/oss-security/2017/10/31/1","https://groups.google.com/forum/#!msg/vim_dev/sRT9BtjLWMk/MZyVYhshBwAJ","https://www.cve.org/CVERecord?id=CVE-2017-1000382"],"bugs":[""],"patches":{"vim":[]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"artful","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000256","published":"2017-10-31T00:00:00","updated_at":"2025-08-25T22:18:35.407660+00:00","description":"\nlibvirt version 2.3.0 and later is vulnerable to a bad default\nconfiguration of \"verify-peer=no\" passed to QEMU by libvirt resulting in a\nfailure to validate SSL/TLS certificates by default.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.redhat.com/archives/libvirt-announce/2017-October/msg00001.html","http://security.libvirt.org/2017/0002.html","https://ubuntu.com/security/notices/USN-3576-1","https://www.cve.org/CVERecord?id=CVE-2017-1000256"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878799"],"patches":{"libvirt":["break-fix: ce61c16450d4992612d1fc6f39a39e79bfccead5 441d3eb6d1be940a67ce45a286602a967601b157","upstream: https://libvirt.org/git/?p=libvirt.git;a=commit;h=441d3eb6d1be940a67ce45a286602a967601b157"]},"tags":{},"packages":[{"name":"libvirt","source":"https://ubuntu.com/security/cve?package=libvirt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvirt","debian":"https://tracker.debian.org/pkg/libvirt","statuses":[{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.8.0-3","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"3.6.0-1ubuntu6.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3576-1"],"notices":[{"id":"USN-3576-1","title":"libvirt vulnerabilities","summary":"Several security issues were fixed in libvirt.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2018-02-20T19:20:53.639085","description":"Vivian Zhang and Christoph Anton Mitterer discovered that libvirt\nincorrectly disabled password authentication when the VNC password was set\nto an empty string. A remote attacker could possibly use this issue to\nbypass authentication, contrary to expectations. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-5008)\n\nDaniel P. Berrange discovered that libvirt incorrectly handled validating\nSSL/TLS certificates. A remote attacker could possibly use this issue to\nobtain sensitive information. This issue only affected Ubuntu 17.10.\n(CVE-2017-1000256)\n\nDaniel P. Berrange and Peter Krempa discovered that libvirt incorrectly\nhandled large QEMU replies. An attacker could possibly use this issue to\ncause libvirt to crash, resulting in a denial of service. (CVE-2018-5748)\n\nPedro Sampaio discovered that libvirt incorrectly handled the libnss_dns.so\nmodule. An attacker in a libvirt_lxc session could possibly use this issue\nto execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and\nUbuntu 17.10. (CVE-2018-6764)\n","is_hidden":false,"release_packages":{"artful":[{"name":"libvirt","version":"3.6.0-1ubuntu6.3","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"3.6.0-1ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/3.6.0-1ubuntu6.3"},{"name":"libvirt0","version":"3.6.0-1ubuntu6.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/3.6.0-1ubuntu6.3"}],"trusty":[{"name":"libvirt","version":"1.2.2-0ubuntu13.1.26","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"1.2.2-0ubuntu13.1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.2.2-0ubuntu13.1.26","pocket":"security"},{"name":"libvirt-dev","version":"1.2.2-0ubuntu13.1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.2.2-0ubuntu13.1.26","pocket":"security"},{"name":"libvirt-doc","version":"1.2.2-0ubuntu13.1.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.2.2-0ubuntu13.1.26","pocket":"security"},{"name":"libvirt0","version":"1.2.2-0ubuntu13.1.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.2.2-0ubuntu13.1.26","pocket":"security"}],"xenial":[{"name":"libvirt","version":"1.3.1-1ubuntu10.19","description":"Libvirt virtualization toolkit","is_source":true},{"name":"libvirt-bin","version":"1.3.1-1ubuntu10.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.19","pocket":"security"},{"name":"libvirt-dev","version":"1.3.1-1ubuntu10.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.19","pocket":"security"},{"name":"libvirt-doc","version":"1.3.1-1ubuntu10.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.19","pocket":"security"},{"name":"libvirt0","version":"1.3.1-1ubuntu10.19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvirt","version_link":"https://launchpad.net/ubuntu/+source/libvirt/1.3.1-1ubuntu10.19","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-5008","CVE-2017-1000256","CVE-2018-5748","CVE-2018-6764"]}]},{"id":"CVE-2017-14919","published":"2017-10-30T19:29:00","updated_at":"2025-08-25T22:26:08.185334+00:00","description":"\nNode.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote\nattackers to cause a denial of service (uncaught exception and crash) by\nleveraging a change in the zlib module 1.2.9 making 8 an invalid value for\nthe windowBits parameter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://nodejs.org/en/blog/vulnerability/oct-2017-dos/","https://www.cve.org/CVERecord?id=CVE-2017-14919"],"bugs":[""],"patches":{"nodejs":[]},"tags":{},"packages":[{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.10.0~dfsg-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.8.5, 6.11.5, 8.8.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2013-4366","published":"2017-10-30T19:29:00","updated_at":"2025-08-25T20:55:37.331840+00:00","description":"\nhttp/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before\n4.3.1 does not ensure that X509HostnameVerifier is not null, which allows\nattackers to have unspecified impact via vectors involving hostname\nverification.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://svn.apache.org/r1528614","http://www.apache.org/dist/httpcomponents/httpclient/RELEASE_NOTES-4.3.x.txt","https://www.cve.org/CVERecord?id=CVE-2013-4366"],"bugs":[""],"patches":{"httpcomponents-client":[]},"tags":{},"packages":[{"name":"httpcomponents-client","source":"https://ubuntu.com/security/cve?package=httpcomponents-client","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=httpcomponents-client","debian":"https://tracker.debian.org/pkg/httpcomponents-client","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.5.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.3.3-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.5.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.5.2-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2012-0881","published":"2017-10-30T16:29:00","updated_at":"2025-07-11T07:37:49.953394+00:00","description":"\nApache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a\ndenial of service (CPU consumption) via a crafted message to an XML\nservice, which triggers hash table collisions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2012-0881"],"bugs":[""],"patches":{"libxerces2-java":[]},"tags":{},"packages":[{"name":"libxerces2-java","source":"https://ubuntu.com/security/cve?package=libxerces2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxerces2-java","debian":"https://tracker.debian.org/pkg/libxerces2-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15597","published":"2017-10-30T14:29:00","updated_at":"2025-08-18T17:06:15.574460+00:00","description":"\nAn issue was discovered in Xen through 4.9.x. Grant copying code made an\nimplication that any grant pin would be accompanied by a suitable page\nreference. Other portions of code, however, did not match up with that\nassumption. When such a grant copy operation is being done on a grant of a\ndying domain, the assumption turns out wrong. A malicious guest\nadministrator can cause hypervisor memory corruption, most likely resulting\nin host crash and a Denial of Service. Privilege escalation and information\nleaks cannot be ruled out.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-236.html","https://www.cve.org/CVERecord?id=CVE-2017-15597"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"groovy","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.9.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.9.2-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3090","published":"2017-10-30T14:29:00","updated_at":"2025-07-17T16:42:42.584291+00:00","description":"\nThe TextParseUtil.translateVariables method in Apache Struts 2.x before\n2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL\nexpression with ANTLR tooling.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Only affectes 2.0.0 to 2.3.16.3"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://struts.apache.org/docs/s2-027.html","https://www.securitytracker.com/id/1035267","https://www.cve.org/CVERecord?id=CVE-2016-3090"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-3249","published":"2017-10-30T14:29:00","updated_at":"2025-08-26T11:52:51.515172+00:00","description":"\nThe HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1\nallows remote attackers to cause a denial of service (out-of-bounds access\nand daemon crash) or possibly execute arbitrary code via vectors related to\nthe (1) frame_handlers array or (2) set_dynamic_table_size function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://mail-archives.us.apache.org/mod_mbox/www-announce/201507.mbox/%3CCABF6JR37mWzDmXDqRQwRUXiojBZrhidndnsY1ZgmcZv-o7-a+g@mail.gmail.com%3E","https://yahoo-security.tumblr.com/post/122883273670/apache-traffic-server-http2-fuzzing","https://www.cve.org/CVERecord?id=CVE-2015-3249"],"bugs":[""],"patches":{"trafficserver":[]},"tags":{},"packages":[{"name":"trafficserver","source":"https://ubuntu.com/security/cve?package=trafficserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trafficserver","debian":"https://tracker.debian.org/pkg/trafficserver","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"7.0.0-5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.3.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-0226","published":"2017-10-30T14:29:00","updated_at":"2025-08-25T21:31:17.181911+00:00","description":"\nApache WSS4J before 1.6.17 and 2.0.x before 2.0.2 improperly leaks\ninformation about decryption failures when decrypting an encrypted key or\nmessage data, which makes it easier for remote attackers to recover the\nplaintext form of a symmetric key via a series of crafted messages. NOTE:\nthis vulnerability exists because of an incomplete fix for CVE-2011-2487.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code isn't present in 1.5.x"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-0226"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777741","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-0226"],"patches":{"wss4j":[]},"tags":{},"packages":[{"name":"wss4j","source":"https://ubuntu.com/security/cve?package=wss4j","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wss4j","debian":"https://tracker.debian.org/pkg/wss4j","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.6.15-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.6.15-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.6.15-2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.5.7-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"1.5.8+svntag-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.15-2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.6.15-2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-0224","published":"2017-10-30T14:29:00","updated_at":"2025-08-04T19:24:31.308375+00:00","description":"\nqpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a\ndenial of service (daemon crash) via a crafted protocol sequence set.\nNOTE: this vulnerability exists because of an incomplete fix for\nCVE-2015-0203.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-0224"],"bugs":[""],"patches":{"qpid-cpp":[]},"tags":{},"packages":[{"name":"qpid-cpp","source":"https://ubuntu.com/security/cve?package=qpid-cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qpid-cpp","debian":"https://tracker.debian.org/pkg/qpid-cpp","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"incomplete fix not applied","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"incomplete fix not applied","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [incomplete fix not applied]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3624","published":"2017-10-30T14:29:00","updated_at":"2025-08-25T21:18:49.932625+00:00","description":"\nApache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass\naccess restrictions by leveraging failure to properly tunnel remap requests\nusing CONNECT.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://issues.apache.org/jira/browse/TS-2677","https://www.cve.org/CVERecord?id=CVE-2014-3624"],"bugs":[""],"patches":{"trafficserver":["upstream: https://git-wip-us.apache.org/repos/asf?p=trafficserver.git;h=33a4771"]},"tags":{},"packages":[{"name":"trafficserver","source":"https://ubuntu.com/security/cve?package=trafficserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trafficserver","debian":"https://tracker.debian.org/pkg/trafficserver","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.1.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"5.1.1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"5.1.1-1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.1.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"5.1.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-16228","published":"2017-10-29T20:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nDulwich before 0.18.5, when an SSH subprocess is used, allows remote\nattackers to execute arbitrary commands via an ssh URL with an initial dash\ncharacter in the hostname, a related issue to CVE-2017-9800,\nCVE-2017-12836, CVE-2017-12976, CVE-2017-1000116, and CVE-2017-1000117.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/","https://tracker.debian.org/news/882440","https://www.dulwich.io/code/dulwich/","https://www.bleepingcomputer.com/news/security/git-project-patches-remote-code-execution-vulnerability-in-git/","https://www.cve.org/CVERecord?id=CVE-2017-16228"],"bugs":[""],"patches":{"dulwich":["upstream: https://www.dulwich.io/code/dulwich/commit/7116a0cbbda571f7dac863f4b1c00b6e16d6d8d6/"]},"tags":{},"packages":[{"name":"dulwich","source":"https://ubuntu.com/security/cve?package=dulwich","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dulwich","debian":"https://tracker.debian.org/pkg/dulwich","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.18.5-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15996","published":"2017-10-29T17:29:00","updated_at":"2025-08-26T11:58:56.483242+00:00","description":"\nelfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause\na denial of service (excessive memory allocation) or possibly have\nunspecified other impact via a crafted ELF file that triggers a \"buffer\noverflow on fuzzed archive header,\" related to an uninitialized variable,\nan improper conditional jump, and the get_archive_member_name,\nprocess_archive_index_and_symbols, and setup_archive functions.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-15996"],"bugs":["https://sourceware.org/bugzilla/show_bug.cgi?id=22361"],"patches":{"binutils":["upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d91f0b20e561e326ee91a09a76206257bde8438b"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"impish","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.30-21ubuntu1~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.31.1-6ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.32-7ubuntu4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.90.20180122-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.32-8ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-15994","published":"2017-10-29T06:29:00","updated_at":"2025-08-25T22:27:31.125574+00:00","description":"\nrsync 3.1.3-development before 2017-10-24 mishandles archaic checksums,\nwhich makes it easier for remote attackers to bypass intended access\nrestrictions. NOTE: the rsync development branch has significant use beyond\nthe rsync developers, e.g., the code has been copied for use in various\nGitHub projects.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced and fixed during 3.1.3 development period"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-15994"],"bugs":[""],"patches":{"rsync":["upstream: https://git.samba.org/?p=rsync.git;a=commit;h=7b8a4ecd6ff9cdf4e5d3850ebf822f1e989255b3","upstream: https://git.samba.org/?p=rsync.git;a=commit;h=c252546ceeb0925eb8a4061315e3ff0a8c55b48b","upstream: https://git.samba.org/?p=rsync.git;a=commit;h=9a480deec4d20277d8e20bc55515ef0640ca1e55","upstream: https://git.samba.org/?p=rsync.git;a=commit;h=bc112b0e7feece62ce98708092306639a8a53cce","upstream: https://git.samba.org/?p=rsync.git;a=commit;h=416e719bea4f5466c8dd2b34cac0059b6ff84ff3"]},"tags":{},"packages":[{"name":"rsync","source":"https://ubuntu.com/security/cve?package=rsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rsync","debian":"https://tracker.debian.org/pkg/rsync","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.1.3-6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":54780,"limit":20,"total_results":79316}