{"cves":[{"id":"CVE-2017-1000116","published":"2017-10-05T01:29:00","updated_at":"2025-08-25T22:18:19.860604+00:00","description":"\nMercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh,\nleading to possible shell-injection attacks.","ubuntu_description":"\nIt was discovered that Mercurial incorrectly handled hostnames passed\nto ssh. An attacker could possibly use this issue to execute arbitrary\ncode.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.282017-08-10.29","https://www.mercurial-scm.org/repo/hg/rev/53224b1ffbc2","https://www.mercurial-scm.org/repo/hg/rev/e10745311406","https://www.mercurial-scm.org/repo/hg/rev/f93975a5ebe8","https://www.mercurial-scm.org/repo/hg/rev/f9134e96ed0f","https://www.mercurial-scm.org/repo/hg/rev/92b583e3e522","https://www.mercurial-scm.org/repo/hg/rev/08cfc4baf3ba","https://www.mercurial-scm.org/repo/hg/rev/55681baf4cf9","https://www.mercurial-scm.org/repo/hg/rev/173ecccb9ee7","https://www.mercurial-scm.org/repo/hg/rev/ca398a50ca00","https://www.mercurial-scm.org/repo/hg/rev/00a75672a9cb","https://www.mercurial-scm.org/repo/hg/rev/943c91326b23","https://www.cve.org/CVERecord?id=CVE-2017-1000116"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871710"],"patches":{"mercurial":[]},"tags":{},"packages":[{"name":"mercurial","source":"https://ubuntu.com/security/cve?package=mercurial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mercurial","debian":"https://tracker.debian.org/pkg/mercurial","statuses":[{"release_codename":"upstream","status":"released","description":"4.3.1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"4.3.1-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.8.2-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.7.3-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000115","published":"2017-10-05T01:29:00","updated_at":"2025-08-25T22:18:19.860604+00:00","description":"\nMercurial prior to version 4.3 is vulnerable to a missing symlink check\nthat can malicious repositories to modify files outside the repository","ubuntu_description":"\nIt was discovered that Mercurial incorrectly handled symlinks. An\nattacker could possibly use this issue to insert, edit or obtain\nsensitive information.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.3_.282017-08-10.29","https://www.cve.org/CVERecord?id=CVE-2017-1000115"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871709"],"patches":{"mercurial":[]},"tags":{},"packages":[{"name":"mercurial","source":"https://ubuntu.com/security/cve?package=mercurial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mercurial","debian":"https://tracker.debian.org/pkg/mercurial","statuses":[{"release_codename":"artful","status":"released","description":"4.3.1-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.8.2-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.7.3-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000099","published":"2017-10-05T01:29:00","updated_at":"2025-08-25T22:18:19.860604+00:00","description":"\nWhen asking to get a file from a file:// URL, libcurl provides a feature\nthat outputs meta-data about the file using HTTP-like headers. The code\ndoing this would send the wrong buffer to the user (stdout or the\napplication's provide callback), which could lead to other private data\nfrom the heap to get inadvertently displayed. The wrong buffer was an\nuninitialized memory area allocated on the heap and if it turned out to not\ncontain any zero byte, it would continue and display the data following\nthat buffer in memory.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"introduced in 7.54.1"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://curl.haxx.se/docs/adv_20170809C.html","https://www.cve.org/CVERecord?id=CVE-2017-1000099"],"bugs":[""],"patches":{"curl":["upstream: https://curl.haxx.se/CVE-2017-1000099.patch"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.55.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000098","published":"2017-10-05T01:29:00","updated_at":"2025-08-26T11:56:45.593880+00:00","description":"\nThe net/http package's Request.ParseMultipartForm method starts writing to\ntemporary files once the request body size surpasses the given \"maxMemory\"\nlimit. It was possible for an attacker to generate a multipart request\ncrafted such that the server ran out of file descriptors.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Packages built using golang need to be rebuilt once the\nvulnerability has been fixed. This CVE entry does not\nlist packages that need rebuilding outside of the main\nrepository or the Ubuntu variants with PPA overlays."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://groups.google.com/forum/#!msg/golang-dev/4NdLzS8sls8/uIz8QlnIBQAJ","https://golang.org/cl/30410","https://www.cve.org/CVERecord?id=CVE-2017-1000098"],"bugs":["https://golang.org/issue/17965"],"patches":{"golang":[],"golang-1.6":[],"golang-1.7":[],"golang-1.8":[],"golang-1.9":[]},"tags":{},"packages":[{"name":"golang","source":"https://ubuntu.com/security/cve?package=golang","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang","debian":"https://tracker.debian.org/pkg/golang","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"golang-1.6","source":"https://ubuntu.com/security/cve?package=golang-1.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.6","debian":"https://tracker.debian.org/pkg/golang-1.6","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"golang-1.7","source":"https://ubuntu.com/security/cve?package=golang-1.7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.7","debian":"https://tracker.debian.org/pkg/golang-1.7","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1.7.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.7.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"golang-1.8","source":"https://ubuntu.com/security/cve?package=golang-1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.8","debian":"https://tracker.debian.org/pkg/golang-1.8","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1.8.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.8.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.8.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"golang-1.9","source":"https://ubuntu.com/security/cve?package=golang-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.9","debian":"https://tracker.debian.org/pkg/golang-1.9","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1.9.1-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.9.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.9.4-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000097","published":"2017-10-05T01:29:00","updated_at":"2025-08-25T22:18:19.860604+00:00","description":"\nOn Darwin, user's trust preferences for root certificates were not honored.\nIf the user had a root certificate loaded in their Keychain that was\nexplicitly not trusted, a Go program would still verify a connection using\nthat root certificate.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Packages built using golang need to be rebuilt once the\nvulnerability has been fixed. This CVE entry does not\nlist packages that need rebuilding outside of the main\nrepository or the Ubuntu variants with PPA overlays."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/golang/go/issues/18141","https://www.cve.org/CVERecord?id=CVE-2017-1000097"],"bugs":[""],"patches":{"golang":[],"golang-1.6":[],"golang-1.7":[],"golang-1.8":[],"golang-1.9":[]},"tags":{},"packages":[{"name":"golang","source":"https://ubuntu.com/security/cve?package=golang","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang","debian":"https://tracker.debian.org/pkg/golang","statuses":[{"release_codename":"upstream","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [Darwin only]","component":null,"pocket":"security"}]},{"name":"golang-1.6","source":"https://ubuntu.com/security/cve?package=golang-1.6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.6","debian":"https://tracker.debian.org/pkg/golang-1.6","statuses":[{"release_codename":"upstream","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [Darwin only]","component":null,"pocket":"security"}]},{"name":"golang-1.7","source":"https://ubuntu.com/security/cve?package=golang-1.7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.7","debian":"https://tracker.debian.org/pkg/golang-1.7","statuses":[{"release_codename":"upstream","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [Darwin only]","component":null,"pocket":"security"}]},{"name":"golang-1.8","source":"https://ubuntu.com/security/cve?package=golang-1.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.8","debian":"https://tracker.debian.org/pkg/golang-1.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"}]},{"name":"golang-1.9","source":"https://ubuntu.com/security/cve?package=golang-1.9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-1.9","debian":"https://tracker.debian.org/pkg/golang-1.9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"Darwin only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15033","published":"2017-10-05T00:00:00","updated_at":"2025-08-25T22:26:17.389714+00:00","description":"\nImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in\ncoders/yuv.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"not fixing memory leak in trusty and xenial"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-15033"],"bugs":["https://github.com/ImageMagick/ImageMagick/pull/756"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/ef8f40689ac452398026c07da41656a7c87e4683"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.11","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-15032","published":"2017-10-05T00:00:00","updated_at":"2025-08-25T22:26:17.389714+00:00","description":"\nImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in\ncoders/ycbcr.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"not fixing memory leak in trusty and xenial"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-15032"],"bugs":["https://github.com/ImageMagick/ImageMagick/pull/752"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/c76e4e14db2a02efdb26be2cd8c190beca68683f","upstream: https://github.com/ImageMagick/ImageMagick/commit/241988ca28139ad970c1d9717c419f41e360ddb0"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.11","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-13722","published":"2017-10-05T00:00:00","updated_at":"2025-08-25T22:24:10.084717+00:00","description":"\nIn the pcfGetProperties function in bitmap/pcfread.c in libXfont through\n1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could\nbe used by local attackers authenticated to an Xserver for a buffer\nover-read, for information disclosure or a crash of the X server.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3442-1","https://www.cve.org/CVERecord?id=CVE-2017-13722"],"bugs":[""],"patches":{"libxfont":["upstream: https://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=672bb944311392e2415b39c0d63b1e1902905bcd"],"libxfont1":[],"libxfont2":[]},"tags":{},"packages":[{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"trusty","status":"released","description":"1:1.4.7-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.5.1-1ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:2.0.1-3ubuntu0.1","component":null,"pocket":"security"}]},{"name":"libxfont1","source":"https://ubuntu.com/security/cve?package=libxfont1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxfont1","debian":"https://tracker.debian.org/pkg/libxfont1","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:1.5.2-4ubuntu0.1","component":null,"pocket":"security"}]},{"name":"libxfont2","source":"https://ubuntu.com/security/cve?package=libxfont2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxfont2","debian":"https://tracker.debian.org/pkg/libxfont2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.0.1-3~ubuntu16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3442-1"],"notices":[{"id":"USN-3442-1","title":"libXfont vulnerabilities","summary":"Several security issues were fixed in libXfont.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2017-10-10T13:02:08.033982","description":"It was discovered that libXfont incorrectly handled certain patterns in\nPatternMatch. A local attacker could use this issue to cause libXfont to\ncrash, resulting in a denial of service, or possibly obtain sensitive\ninformation. (CVE-2017-13720)\n\nIt was discovered that libXfont incorrectly handled certain malformed PCF\nfiles. A local attacker could use this issue to cause libXfont to crash,\nresulting in a denial of service, or possibly obtain sensitive information.\n(CVE-2017-13722)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxfont","version":"1:1.4.7-1ubuntu0.3","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont-dev","version":"1:1.4.7-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.3","pocket":"security"},{"name":"libxfont1","version":"1:1.4.7-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.3","pocket":"security"},{"name":"libxfont1-udeb","version":"1:1.4.7-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.3","pocket":"security"}],"xenial":[{"name":"libxfont","version":"1:1.5.1-1ubuntu0.16.04.3","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont2","version":"1:2.0.1-3~ubuntu16.04.2","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont-dev","version":"1:2.0.1-3~ubuntu16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont2","version_link":"https://launchpad.net/ubuntu/+source/libxfont2/1:2.0.1-3~ubuntu16.04.2","pocket":"security"},{"name":"libxfont1","version":"1:1.5.1-1ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.5.1-1ubuntu0.16.04.3","pocket":"security"},{"name":"libxfont1-dev","version":"1:1.5.1-1ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.5.1-1ubuntu0.16.04.3","pocket":"security"},{"name":"libxfont1-udeb","version":"1:1.5.1-1ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.5.1-1ubuntu0.16.04.3","pocket":"security"},{"name":"libxfont2","version":"1:2.0.1-3~ubuntu16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont2","version_link":"https://launchpad.net/ubuntu/+source/libxfont2/1:2.0.1-3~ubuntu16.04.2","pocket":"security"},{"name":"libxfont2-udeb","version":"1:2.0.1-3~ubuntu16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont2","version_link":"https://launchpad.net/ubuntu/+source/libxfont2/1:2.0.1-3~ubuntu16.04.2","pocket":"security"}],"zesty":[{"name":"libxfont","version":"1:2.0.1-3ubuntu0.1","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont1","version":"1:1.5.2-4ubuntu0.1","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont1","version":"1:1.5.2-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont1","version_link":"https://launchpad.net/ubuntu/+source/libxfont1/1:1.5.2-4ubuntu0.1"},{"name":"libxfont2","version":"1:2.0.1-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:2.0.1-3ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-13720","CVE-2017-13722"]}]},{"id":"CVE-2017-13720","published":"2017-10-05T00:00:00","updated_at":"2025-08-25T22:24:10.084717+00:00","description":"\nIn the PatternMatch function in fontfile/fontdir.c in libXfont through\n1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can\ncause a buffer over-read during pattern matching of fonts, leading to\ninformation disclosure or a crash (denial of service). This occurs because\n'\\0' characters are incorrectly skipped in situations involving ?\ncharacters.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3442-1","https://www.cve.org/CVERecord?id=CVE-2017-13720"],"bugs":[""],"patches":{"libxfont":["upstream: https://cgit.freedesktop.org/xorg/lib/libXfont/commit/?id=d1e670a4a8704b8708e493ab6155589bcd570608"],"libxfont1":[],"libxfont2":[]},"tags":{},"packages":[{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.4.7-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.5.1-1ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:2.0.1-3ubuntu0.1","component":null,"pocket":"security"}]},{"name":"libxfont1","source":"https://ubuntu.com/security/cve?package=libxfont1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxfont1","debian":"https://tracker.debian.org/pkg/libxfont1","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:1.5.2-4ubuntu0.1","component":null,"pocket":"security"}]},{"name":"libxfont2","source":"https://ubuntu.com/security/cve?package=libxfont2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libxfont2","debian":"https://tracker.debian.org/pkg/libxfont2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.0.1-3~ubuntu16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3442-1"],"notices":[{"id":"USN-3442-1","title":"libXfont vulnerabilities","summary":"Several security issues were fixed in libXfont.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2017-10-10T13:02:08.033982","description":"It was discovered that libXfont incorrectly handled certain patterns in\nPatternMatch. A local attacker could use this issue to cause libXfont to\ncrash, resulting in a denial of service, or possibly obtain sensitive\ninformation. (CVE-2017-13720)\n\nIt was discovered that libXfont incorrectly handled certain malformed PCF\nfiles. A local attacker could use this issue to cause libXfont to crash,\nresulting in a denial of service, or possibly obtain sensitive information.\n(CVE-2017-13722)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxfont","version":"1:1.4.7-1ubuntu0.3","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont-dev","version":"1:1.4.7-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.3","pocket":"security"},{"name":"libxfont1","version":"1:1.4.7-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.3","pocket":"security"},{"name":"libxfont1-udeb","version":"1:1.4.7-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.4.7-1ubuntu0.3","pocket":"security"}],"xenial":[{"name":"libxfont","version":"1:1.5.1-1ubuntu0.16.04.3","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont2","version":"1:2.0.1-3~ubuntu16.04.2","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont-dev","version":"1:2.0.1-3~ubuntu16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont2","version_link":"https://launchpad.net/ubuntu/+source/libxfont2/1:2.0.1-3~ubuntu16.04.2","pocket":"security"},{"name":"libxfont1","version":"1:1.5.1-1ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.5.1-1ubuntu0.16.04.3","pocket":"security"},{"name":"libxfont1-dev","version":"1:1.5.1-1ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.5.1-1ubuntu0.16.04.3","pocket":"security"},{"name":"libxfont1-udeb","version":"1:1.5.1-1ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:1.5.1-1ubuntu0.16.04.3","pocket":"security"},{"name":"libxfont2","version":"1:2.0.1-3~ubuntu16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont2","version_link":"https://launchpad.net/ubuntu/+source/libxfont2/1:2.0.1-3~ubuntu16.04.2","pocket":"security"},{"name":"libxfont2-udeb","version":"1:2.0.1-3~ubuntu16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libxfont2","version_link":"https://launchpad.net/ubuntu/+source/libxfont2/1:2.0.1-3~ubuntu16.04.2","pocket":"security"}],"zesty":[{"name":"libxfont","version":"1:2.0.1-3ubuntu0.1","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont1","version":"1:1.5.2-4ubuntu0.1","description":"X11 font rasterisation library","is_source":true},{"name":"libxfont1","version":"1:1.5.2-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont1","version_link":"https://launchpad.net/ubuntu/+source/libxfont1/1:1.5.2-4ubuntu0.1"},{"name":"libxfont2","version":"1:2.0.1-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxfont","version_link":"https://launchpad.net/ubuntu/+source/libxfont/1:2.0.1-3ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-13720","CVE-2017-13722"]}]},{"id":"CVE-2017-12173","published":"2017-10-05T00:00:00","updated_at":"2025-08-25T22:21:47.623475+00:00","description":"\nIt was found that sssd's sysdb_search_user_by_upn_res() function before\n1.16.0 did not sanitize requests when querying its local cache and was\nvulnerable to injection. In a centralized login environment, if a password\nhash was locally cached for a given user, an authenticated attacker could\nuse this flaw to retrieve it.","ubuntu_description":"","notes":[{"author":"leosilva","note":"according with RHEL \"Versions prior to sssd-1.12.0 are\nnot affected (affected commit: 7ecb5ae)\""}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1498173","https://ubuntu.com/security/notices/USN-3526-1","https://www.cve.org/CVERecord?id=CVE-2017-12173"],"bugs":[""],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"artful","status":"released","description":"1.15.3-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.13.4-1ubuntu1.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.15.2-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":["USN-3526-1"],"notices":[{"id":"USN-3526-1","title":"SSSD vulnerability","summary":"SSSD could be made to expose sensitive information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-01-10T12:57:14.506582","description":"It was discovered that SSSD incorrectly handled certain inputs when querying\nits local cache. An attacker could use this to inject arbitrary code and expose\nsensitive information.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"sssd","version":"1.13.4-1ubuntu1.10","description":"System Security Services Daemon -- metapackage","is_source":true},{"name":"libipa-hbac-dev","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libipa-hbac0","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libnss-sss","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libpam-sss","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-idmap-dev","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-idmap0","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-nss-idmap0","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-simpleifp-dev","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-simpleifp0","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libsss-sudo","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libwbclient-sssd","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"libwbclient-sssd-dev","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"python-libipa-hbac","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"python-libsss-nss-idmap","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"python-sss","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"python3-libipa-hbac","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"python3-sss","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-ad","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-ad-common","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-common","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-dbus","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-ipa","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-krb5","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-krb5-common","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-ldap","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-proxy","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"},{"name":"sssd-tools","version":"1.13.4-1ubuntu1.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.13.4-1ubuntu1.10","pocket":"security"}],"zesty":[{"name":"sssd","version":"1.15.2-1ubuntu1.1","description":"System Security Services Daemon -- metapackage","is_source":true},{"name":"sssd","version":"1.15.2-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.15.2-1ubuntu1.1"},{"name":"sssd-common","version":"1.15.2-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.15.2-1ubuntu1.1"},{"name":"sssd-tools","version":"1.15.2-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.15.2-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2017-12173"]}]},{"id":"CVE-2017-12149","published":"2017-10-04T21:01:00","updated_at":"2025-07-17T16:42:54.213282+00:00","description":"\nIn Jboss Application Server as shipped with Red Hat Enterprise Application\nPlatform 5.2, it was found that the doFilter method in the\nReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for\nwhich it performs deserialization and thus allowing an attacker to execute\narbitrary code via crafted serialized data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1486220","https://www.cve.org/CVERecord?id=CVE-2017-12149","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"jbossas4":[]},"tags":{},"packages":[{"name":"jbossas4","source":"https://ubuntu.com/security/cve?package=jbossas4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jbossas4","debian":"https://tracker.debian.org/pkg/jbossas4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15011","published":"2017-10-04T01:29:00","updated_at":"2025-07-17T16:42:55.697033+00:00","description":"\nThe named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and\nSugarSync, are configured for remote access and allow remote attackers to\ncause a denial of service (application crash) via an unspecified string.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"Likely specific to the Windows Named Pipes interface"},{"author":"debian","note":"Only affects Windows"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://hackinparis.com/data/slides/2017/2017_Cohen_Gil_The_forgotten_interface_Windows_named_pipes.pdf","https://www.youtube.com/watch?v=m6zISgWPGGY","https://www.cve.org/CVERecord?id=CVE-2017-15011"],"bugs":[""],"patches":{"qbittorrent":[]},"tags":{},"packages":[{"name":"qbittorrent","source":"https://ubuntu.com/security/cve?package=qbittorrent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qbittorrent","debian":"https://tracker.debian.org/pkg/qbittorrent","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"affects Windows","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"affects Windows","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"affects Windows","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"affects Windows","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [affects Windows]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-15010","published":"2017-10-04T01:29:00","updated_at":"2025-08-26T11:58:41.701548+00:00","description":"\nA ReDoS (regular expression denial of service) flaw was found in the\ntough-cookie module before 2.3.3 for Node.js. An attacker that is able to\nmake an HTTP request using a specially crafted cookie may cause the\napplication to consume an excessive amount of CPU.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/salesforce/tough-cookie/issues/92","https://nodesecurity.io/advisories/525","https://snyk.io/vuln/npm:tough-cookie:20170905","https://www.cve.org/CVERecord?id=CVE-2017-15010"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=877660"],"patches":{"node-tough-cookie":[]},"tags":{},"packages":[{"name":"node-tough-cookie","source":"https://ubuntu.com/security/cve?package=node-tough-cookie","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-tough-cookie","debian":"https://tracker.debian.org/pkg/node-tough-cookie","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.3.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-14997","published":"2017-10-04T01:29:00","updated_at":"2025-08-25T22:26:13.020351+00:00","description":"\nGraphicsMagick 1.3.26 allows remote attackers to cause a denial of service\n(excessive memory allocation) because of an integer underflow in\nReadPICTImage in coders/pict.c.","ubuntu_description":"\nIt was discovered that GraphicsMagick incorrectly handled certain image\nfiles. An attacker could possibly use this issue to cause a denial of\nservice or other unspecified impact.","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/graphicsmagick/code/ci/0683f8724200495059606c03f04e0d589b33ebe8/","https://sourceforge.net/p/graphicsmagick/bugs/511/","http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=0683f8724200","https://ubuntu.com/security/notices/USN-4232-1","https://www.cve.org/CVERecord?id=CVE-2017-14997"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.23-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.18-1ubuntu3.1+esm4","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4232-1"],"notices":[{"id":"USN-4232-1","title":"GraphicsMagick vulnerabilities","summary":"Several security issues were fixed in GraphicsMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-01-08T17:42:19.392930","description":"It was discovered that GraphicsMagick incorrectly handled certain image files.\nAn attacker could possibly use this issue to cause a denial of service or other\nunspecified impact.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"graphicsmagick","version":"1.3.23-1ubuntu0.4","description":"collection of image processing tools","is_source":true},{"name":"graphicsmagick","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"graphicsmagick-imagemagick-compat","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"graphicsmagick-libmagick-dev-compat","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphics-magick-perl","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick++-q16-12","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick++1-dev","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick-q16-3","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick1-dev","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14165","CVE-2017-14314","CVE-2017-14504","CVE-2017-14649","CVE-2017-14733","CVE-2017-14994","CVE-2017-14997","CVE-2017-15277","CVE-2017-15930","CVE-2017-16352","CVE-2017-16353"]}]},{"id":"CVE-2017-14994","published":"2017-10-04T01:29:00","updated_at":"2025-08-25T22:26:13.020351+00:00","description":"\nReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote\nattackers to cause a denial of service (NULL pointer dereference) via a\ncrafted DICOM image, related to the ability of DCM_ReadNonNativeImages to\nyield an image list with zero frames.","ubuntu_description":"\nIt was discovered that GraphicsMagick incorrectly handled certain image\nfiles. An attacker could possibly use this issue to cause a denial of\nservice or other unspecified impact.","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=b3eca3eaa264","https://sourceforge.net/p/graphicsmagick/bugs/512/","https://nandynarwhals.org/CVE-2017-14994/","https://ubuntu.com/security/notices/USN-4232-1","https://www.cve.org/CVERecord?id=CVE-2017-14994"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.18-1ubuntu3.1+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.23-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.3.26-13","component":null,"pocket":"security"}]}],"notices_ids":["USN-4232-1"],"notices":[{"id":"USN-4232-1","title":"GraphicsMagick vulnerabilities","summary":"Several security issues were fixed in GraphicsMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-01-08T17:42:19.392930","description":"It was discovered that GraphicsMagick incorrectly handled certain image files.\nAn attacker could possibly use this issue to cause a denial of service or other\nunspecified impact.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"graphicsmagick","version":"1.3.23-1ubuntu0.4","description":"collection of image processing tools","is_source":true},{"name":"graphicsmagick","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"graphicsmagick-imagemagick-compat","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"graphicsmagick-libmagick-dev-compat","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphics-magick-perl","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick++-q16-12","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick++1-dev","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick-q16-3","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"},{"name":"libgraphicsmagick1-dev","version":"1.3.23-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/graphicsmagick","version_link":"https://launchpad.net/ubuntu/+source/graphicsmagick/1.3.23-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14165","CVE-2017-14314","CVE-2017-14504","CVE-2017-14649","CVE-2017-14733","CVE-2017-14994","CVE-2017-14997","CVE-2017-15277","CVE-2017-15930","CVE-2017-16352","CVE-2017-16353"]}]},{"id":"CVE-2017-12166","published":"2017-10-04T01:29:00","updated_at":"2025-08-25T22:21:42.404335+00:00","description":"\nOpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a\nbuffer overflow vulnerability when key-method 1 is used, possibly resulting\nin code execution.","ubuntu_description":"\nsbeattie> vulnerable only in configurations that have 'key method 1’ set.","notes":[],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://community.openvpn.net/openvpn/wiki/CVE-2017-12166","http://www.openwall.com/lists/oss-security/2017/09/28/2","https://www.cve.org/CVERecord?id=CVE-2017-12166","https://ubuntu.com/security/notices/USN-7340-1"],"bugs":[""],"patches":{"openvpn":["upstream: https://community.openvpn.net/openvpn/changeset/3b1a61e9fb27213c46f76312f4065816bee8ed01/","upstream: https://community.openvpn.net/openvpn/changeset/c7e259160b28e94e4ea7f0ef767f8134283af255/","upstream: https://community.openvpn.net/openvpn/changeset/fce34375295151f548a26c2d0eb30141e427c81a/","upstream: https://community.openvpn.net/openvpn/changeset/a9f5c744d6b09f2495ca48d2c926efd3a4b981e6/"]},"tags":{},"packages":[{"name":"openvpn","source":"https://ubuntu.com/security/cve?package=openvpn","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openvpn","debian":"https://tracker.debian.org/pkg/openvpn","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.10-1ubuntu2.2+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"kinetic","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.4.4-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.4, 2.3.18","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.4.7-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.3.2-7ubuntu3.2+esm2","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-7340-1"],"notices":[{"id":"USN-7340-1","title":"OpenVPN vulnerabilities","summary":"Several security issues were fixed in OpenVPN.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2025-03-11T03:13:12.230531","description":"It was discovered that OpenVPN did not perform proper input validation\nwhen generating a TLS key under certain configuration, which could lead to\na buffer overflow. An attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS, Ubuntu 16.04 LTS. (CVE-2017-12166)\n\nReynir Björnsson discovered that OpenVPN incorrectly handled certain\ncontrol channel messages with nonprintable characters. A remote attacker\ncould possibly use this issue to cause OpenVPN to consume resources, or\nfill up log files with garbage, leading to a denial of service.\n(CVE-2024-5594)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openvpn","version":"2.4.4-2ubuntu1.7+esm1","description":"virtual private network software","is_source":true},{"name":"openvpn","version":"2.4.4-2ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvpn","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openvpn","version":"2.3.2-7ubuntu3.2+esm2","description":"virtual private network software","is_source":true},{"name":"openvpn","version":"2.3.2-7ubuntu3.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvpn","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openvpn","version":"2.3.10-1ubuntu2.2+esm2","description":"virtual private network software","is_source":true},{"name":"openvpn","version":"2.3.10-1ubuntu2.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvpn","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2024-5594","CVE-2017-12166"]}]},{"id":"CVE-2017-0823","published":"2017-10-04T01:29:00","updated_at":"2025-07-17T16:42:47.267953+00:00","description":"\nAn information disclosure vulnerability in the Android system (rild).\nProduct: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1,\n7.1.2. Android ID: A-37896655.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://android.googlesource.com/platform/hardware/ril/+/cd5f15f588a5d27e99ba12f057245bfe507f8c42","https://source.android.com/security/bulletin/pixel/2017-10-01","https://www.cve.org/CVERecord?id=CVE-2017-0823"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0822","published":"2017-10-04T01:29:00","updated_at":"2025-08-25T22:17:46.162823+00:00","description":"\nAn elevation of privilege vulnerability in the Android system (camera).\nProduct: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID:\nA-63787722.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"We do not support security updates for Android components,\nmarking as ignored."}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-0822"],"bugs":[""],"patches":{"android-framework-23":[]},"tags":{},"packages":[{"name":"android-framework-23","source":"https://ubuntu.com/security/cve?package=android-framework-23","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=android-framework-23","debian":"https://tracker.debian.org/pkg/android-framework-23","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0820","published":"2017-10-04T01:29:00","updated_at":"2025-07-17T16:42:47.267953+00:00","description":"\nA vulnerability in the Android media framework (n/a). Product: Android.\nVersions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187433.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://android.googlesource.com/platform/frameworks/av/+/8a3a2f6ea7defe1a81bb32b3c9f3537f84749b9d","https://source.android.com/security/bulletin/pixel/2017-10-01","https://www.cve.org/CVERecord?id=CVE-2017-0820"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0819","published":"2017-10-04T01:29:00","updated_at":"2025-07-17T16:42:47.267953+00:00","description":"\nA vulnerability in the Android media framework (n/a). Product: Android.\nVersions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63045918.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://android.googlesource.com/platform/external/libhevc/+/87fb7909c49e6a4510ba86ace1ffc83459c7e1b9","https://source.android.com/security/bulletin/pixel/2017-10-01","https://www.cve.org/CVERecord?id=CVE-2017-0819"],"bugs":[""],"patches":{"android":[]},"tags":{},"packages":[{"name":"android","source":"https://ubuntu.com/security/cve?package=android","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=android","debian":"https://tracker.debian.org/pkg/android","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":55140,"limit":20,"total_results":79316}