{"cves":[{"id":"CVE-2017-14634","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:42.890047+00:00","description":"\nIn libsndfile 1.0.28, a divide-by-zero error exists in the function\ndouble64_init() in double64.c, which may lead to DoS when playing a crafted\naudio file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"double64_init-Check-psf-sf.channels-against-upper-bo.patch"}],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4013-1","https://ubuntu.com/security/notices/USN-4704-1","https://www.cve.org/CVERecord?id=CVE-2017-14634"],"bugs":["https://github.com/erikd/libsndfile/issues/318"],"patches":{"libsndfile":["proposed: https://github.com/erikd/libsndfile/pull/327","upstream: https://github.com/erikd/libsndfile/commit/85c877d5072866aadbe8ed0c3e0590fbb5e16788"]},"tags":{},"packages":[{"name":"libsndfile","source":"https://ubuntu.com/security/cve?package=libsndfile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsndfile","debian":"https://tracker.debian.org/pkg/libsndfile","statuses":[{"release_codename":"groovy","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.25-7ubuntu2.2+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.28-4ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.28-4ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.28-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.25-10ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-4013-1","USN-4704-1"],"notices":[{"id":"USN-4013-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2019-06-10T14:08:57.040401","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.04.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.10.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.2","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14245","CVE-2017-14246","CVE-2017-14634","CVE-2017-16942","CVE-2017-17456","CVE-2017-17457","CVE-2017-6892","CVE-2018-13139","CVE-2018-19432","CVE-2018-19661","CVE-2018-19662","CVE-2018-19758","CVE-2019-3832"]},{"id":"USN-4704-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2021-01-26T16:23:13.203532","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-12562)\n\nIt was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-14245,\nCVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892,\nCVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662,\nCVE-2018-19758, CVE-2019-3832)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libsndfile","version":"1.0.25-7ubuntu2.2+esm1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"libsndfile1-dev","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"sndfile-programs","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.3","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12562","CVE-2018-19758","CVE-2018-19661","CVE-2017-16942","CVE-2017-6892","CVE-2018-19432","CVE-2018-19662","CVE-2017-14246","CVE-2017-14634","CVE-2019-3832","CVE-2018-13139","CVE-2017-14245"]}]},{"id":"CVE-2017-14633","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:38.208047+00:00","description":"\nIn Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability\nexists in the function mapping0_forward() in mapping0.c, which may lead to\nDoS when operating on a crafted audio file with vorbis_analysis().","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3569-1","https://www.cve.org/CVERecord?id=CVE-2017-14633"],"bugs":["https://gitlab.xiph.org/xiph/vorbis/issues/2329","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876778","https://bugs.launchpad.net/ubuntu/+source/libvorbis/+bug/1756516"],"patches":{"libvorbis":[]},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"artful","status":"released","description":"1.3.5-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.2-1.3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.5-4.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.5-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3569-1"],"notices":[{"id":"USN-3569-1","title":"libvorbis vulnerabilities","summary":"Several security issues were fixed in libvorbis.\n","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2018-02-13T18:49:22.921466","description":"It was discovered that libvorbis incorrectly handled certain sound files.\nAn attacker could possibly use this to execute arbitrary code.\n(CVE-2017-14632)\n\nIt was discovered that libvorbis incorrectly handled certain sound files.\nAn attacker could use this to cause a denial of service.\n(CVE-2017-14633)\n","is_hidden":false,"release_packages":{"artful":[{"name":"libvorbis","version":"1.3.5-4ubuntu0.1","description":"The Vorbis General Audio Compression Codec","is_source":true},{"name":"libvorbis0a","version":"1.3.5-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-4ubuntu0.1"}],"trusty":[{"name":"libvorbis","version":"1.3.2-1.3ubuntu1.1","description":"The Vorbis General Audio Compression Codec","is_source":true},{"name":"libvorbis-dev","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"},{"name":"libvorbis0a","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"},{"name":"libvorbisenc2","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"},{"name":"libvorbisfile3","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"}],"xenial":[{"name":"libvorbis","version":"1.3.5-3ubuntu0.1","description":"The Vorbis General Audio Compression Codec","is_source":true},{"name":"libvorbis-dev","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"},{"name":"libvorbis0a","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"},{"name":"libvorbisenc2","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"},{"name":"libvorbisfile3","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14632","CVE-2017-14633"]}]},{"id":"CVE-2017-14632","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:38.208047+00:00","description":"\nXiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing\nuninitialized memory in the function vorbis_analysis_headerout() in info.c\nwhen vi->channels<=0, a similar issue to Mozilla bug 550184.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3569-1","https://www.cve.org/CVERecord?id=CVE-2017-14632"],"bugs":["https://gitlab.xiph.org/xiph/vorbis/issues/2328","https://github.com/xiph/vorbis/issues/29","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876779","https://bugs.launchpad.net/ubuntu/+source/libvorbis/+bug/1756516"],"patches":{"libvorbis":[]},"tags":{},"packages":[{"name":"libvorbis","source":"https://ubuntu.com/security/cve?package=libvorbis","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvorbis","debian":"https://tracker.debian.org/pkg/libvorbis","statuses":[{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"1.3.5-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.2-1.3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.5-4.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.5-3ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3569-1"],"notices":[{"id":"USN-3569-1","title":"libvorbis vulnerabilities","summary":"Several security issues were fixed in libvorbis.\n","instructions":"After a standard system upgrade you need to restart any applications that\nuse libvorbis, such as Totem and gtkpod, to effect the necessary changes.\n","references":[],"published":"2018-02-13T18:49:22.921466","description":"It was discovered that libvorbis incorrectly handled certain sound files.\nAn attacker could possibly use this to execute arbitrary code.\n(CVE-2017-14632)\n\nIt was discovered that libvorbis incorrectly handled certain sound files.\nAn attacker could use this to cause a denial of service.\n(CVE-2017-14633)\n","is_hidden":false,"release_packages":{"artful":[{"name":"libvorbis","version":"1.3.5-4ubuntu0.1","description":"The Vorbis General Audio Compression Codec","is_source":true},{"name":"libvorbis0a","version":"1.3.5-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-4ubuntu0.1"}],"trusty":[{"name":"libvorbis","version":"1.3.2-1.3ubuntu1.1","description":"The Vorbis General Audio Compression Codec","is_source":true},{"name":"libvorbis-dev","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"},{"name":"libvorbis0a","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"},{"name":"libvorbisenc2","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"},{"name":"libvorbisfile3","version":"1.3.2-1.3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.2-1.3ubuntu1.1","pocket":"security"}],"xenial":[{"name":"libvorbis","version":"1.3.5-3ubuntu0.1","description":"The Vorbis General Audio Compression Codec","is_source":true},{"name":"libvorbis-dev","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"},{"name":"libvorbis0a","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"},{"name":"libvorbisenc2","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"},{"name":"libvorbisfile3","version":"1.3.5-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvorbis","version_link":"https://launchpad.net/ubuntu/+source/libvorbis/1.3.5-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14632","CVE-2017-14633"]}]},{"id":"CVE-2017-14626","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:38.208047+00:00","description":"\nImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the\nfunction sixel_decode in coders/sixel.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code not present in trusty"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-14626"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/720","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878524"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/90b301db18434b2c2228776d06c2898b5fed74f0"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-14625","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:38.208047+00:00","description":"\nImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the\nfunction sixel_output_create in coders/sixel.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code not present in trusty"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-14625"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/721","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=877355"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/cc797c296c30f3ec31cd02418b58a2c27549b0a9"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-14624","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:38.208047+00:00","description":"\nImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the\nfunction PostscriptDelegateMessage in coders/ps.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"code not present in trusty"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-14624"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/722","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=877354"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/9ff805077fd5297dc41dc989f9dba59877e12f97"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"artful","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.9.34+dfsg-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-14246","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:10.151579+00:00","description":"\nAn out of bounds read in the function d2ulaw_array() in ulaw.c of\nlibsndfile 1.0.28 may lead to a remote DoS attack or information\ndisclosure, related to mishandling of the NAN and INFINITY floating-point\nvalues.","ubuntu_description":"","notes":[{"author":"leosilva","note":"reproducer can be found in github link"},{"author":"mdeslaur","note":"a-ulaw-fix-multiple-buffer-overflows-432.patch"}],"codename":null,"priority":"low","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4013-1","https://ubuntu.com/security/notices/USN-4704-1","https://www.cve.org/CVERecord?id=CVE-2017-14246"],"bugs":["https://github.com/erikd/libsndfile/issues/344","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884735","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876682","https://github.com/erikd/libsndfile/issues/317"],"patches":{"libsndfile":["upstream: https://github.com/erikd/libsndfile/commit/8ddc442d539ca775d80cdbc7af17a718634a743f"]},"tags":{},"packages":[{"name":"libsndfile","source":"https://ubuntu.com/security/cve?package=libsndfile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsndfile","debian":"https://tracker.debian.org/pkg/libsndfile","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.28-4ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.28-4ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.28-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.25-10ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.25-7ubuntu2.2+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4013-1","USN-4704-1"],"notices":[{"id":"USN-4013-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2019-06-10T14:08:57.040401","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.04.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.10.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.2","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14245","CVE-2017-14246","CVE-2017-14634","CVE-2017-16942","CVE-2017-17456","CVE-2017-17457","CVE-2017-6892","CVE-2018-13139","CVE-2018-19432","CVE-2018-19661","CVE-2018-19662","CVE-2018-19758","CVE-2019-3832"]},{"id":"USN-4704-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2021-01-26T16:23:13.203532","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-12562)\n\nIt was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-14245,\nCVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892,\nCVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662,\nCVE-2018-19758, CVE-2019-3832)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libsndfile","version":"1.0.25-7ubuntu2.2+esm1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"libsndfile1-dev","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"sndfile-programs","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.3","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12562","CVE-2018-19758","CVE-2018-19661","CVE-2017-16942","CVE-2017-6892","CVE-2018-19432","CVE-2018-19662","CVE-2017-14246","CVE-2017-14634","CVE-2019-3832","CVE-2018-13139","CVE-2017-14245"]}]},{"id":"CVE-2017-14245","published":"2017-09-21T00:00:00","updated_at":"2025-08-25T22:25:10.151579+00:00","description":"\nAn out of bounds read in the function d2alaw_array() in alaw.c of\nlibsndfile 1.0.28 may lead to a remote DoS attack or information\ndisclosure, related to mishandling of the NAN and INFINITY floating-point\nvalues.","ubuntu_description":"","notes":[{"author":"leosilva","note":"reproducer can be found in github link"},{"author":"mdeslaur","note":"a-ulaw-fix-multiple-buffer-overflows-432.patch"}],"codename":null,"priority":"low","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4013-1","https://ubuntu.com/security/notices/USN-4704-1","https://www.cve.org/CVERecord?id=CVE-2017-14245"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876682","https://github.com/erikd/libsndfile/issues/317","https://github.com/erikd/libsndfile/issues/344","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884735"],"patches":{"libsndfile":["upstream: https://github.com/erikd/libsndfile/commit/8ddc442d539ca775d80cdbc7af17a718634a743f"]},"tags":{},"packages":[{"name":"libsndfile","source":"https://ubuntu.com/security/cve?package=libsndfile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsndfile","debian":"https://tracker.debian.org/pkg/libsndfile","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.28-4ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1.0.28-4ubuntu0.18.10.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.28-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.25-10ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.0.28-6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.25-7ubuntu2.2+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4013-1","USN-4704-1"],"notices":[{"id":"USN-4013-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2019-06-10T14:08:57.040401","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.04.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.04.1","pocket":"security"}],"cosmic":[{"name":"libsndfile","version":"1.0.28-4ubuntu0.18.10.1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"libsndfile1-dev","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"},{"name":"sndfile-programs","version":"1.0.28-4ubuntu0.18.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.28-4ubuntu0.18.10.1"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.2","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-14245","CVE-2017-14246","CVE-2017-14634","CVE-2017-16942","CVE-2017-17456","CVE-2017-17457","CVE-2017-6892","CVE-2018-13139","CVE-2018-19432","CVE-2018-19661","CVE-2018-19662","CVE-2018-19758","CVE-2019-3832"]},{"id":"USN-4704-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2021-01-26T16:23:13.203532","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-12562)\n\nIt was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-14245,\nCVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892,\nCVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662,\nCVE-2018-19758, CVE-2019-3832)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libsndfile","version":"1.0.25-7ubuntu2.2+esm1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"libsndfile1-dev","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"sndfile-programs","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.3","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12562","CVE-2018-19758","CVE-2018-19661","CVE-2017-16942","CVE-2017-6892","CVE-2018-19432","CVE-2018-19662","CVE-2017-14246","CVE-2017-14634","CVE-2019-3832","CVE-2018-13139","CVE-2017-14245"]}]},{"id":"CVE-2017-12153","published":"2017-09-21T00:00:00","updated_at":"2026-07-04T07:41:49.254498+00:00","description":"\nA security flaw was discovered in the nl80211_set_rekey_data() function in\nnet/wireless/nl80211.c in the Linux kernel through 4.13.3. This function\ndoes not check whether the required attributes are present in a Netlink\nrequest. This request can be issued by a user with the CAP_NET_ADMIN\ncapability and may result in a NULL pointer dereference and system crash.","ubuntu_description":"\nBo Zhang discovered that the netlink wireless configuration interface in\nthe Linux kernel did not properly validate attributes when handling certain\nrequests. A local attacker with the CAP_NET_ADMIN could use this to cause a\ndenial of service (system crash).","notes":[{"author":"sbeattie","note":"attacker needs CAP_NET_ADMIN either at system level or in a\nnamespace that also has had a WiFi interface moved into it."}],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://marc.info/?t=150525503100001&r=1&w=2","https://marc.info/?l=linux-wireless&m=150525493517953&w=2","https://git.kernel.org/pub/scm/linux/kernel/git/jberg/mac80211.git/commit/?id=e785fa0a164aa11001cba931367c7f94ffaff888","https://ubuntu.com/security/notices/USN-3469-1","https://ubuntu.com/security/notices/USN-3469-2","https://ubuntu.com/security/notices/USN-3487-1","https://ubuntu.com/security/notices/USN-3583-1","https://ubuntu.com/security/notices/USN-3583-2","https://www.cve.org/CVERecord?id=CVE-2017-12153"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1491046"],"patches":{"linux":["break-fix: e5497d766adb92bcbd1fa4a147e188f84f34b20a e785fa0a164aa11001cba931367c7f94ffaff888"],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gkeop":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-nvidia":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oem-6.8":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-xilinx-zynqmp":[],"linux-aws-6.8":[],"linux-gcp-6.8":[],"linux-oracle-6.8":[],"linux-azure-6.8":[],"linux-oem-6.11":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"released","description":"4.13.0-17.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-142.191","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-98.121","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-17.20","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-20.21","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1039.48","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1007.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1008.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1005.7","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-azure-fde-5.15]","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1019.24~20.04.1.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.22~recert1","component":null,"pocket":"fips"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1002.5","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1006.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1033.33","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1008.9","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-32.35~16.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-26.29~16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.0.0-15.16~18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1009.14","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1008.8","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needs-triage]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-98.121~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.5.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1005.5","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"released","description":"4.13.0-1006.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1076.84","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life, was pending","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1006.6","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1010.11","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [replaced by linux-raspi]","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.1-1015.16","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-riscv-5.8]","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"released","description":"4.4.0-1078.83","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1078.83","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.4.0-1078.83","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc2, 4.4.90","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3487-1","USN-3583-2","USN-3469-1","USN-3469-2","USN-3583-1"],"notices":[{"id":"USN-3487-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-11-21T17:59:53.709343","description":"It was discovered that the KVM subsystem in the Linux kernel did not\nproperly keep track of nested levels in guest page tables. A local attacker\nin a guest VM could use this to cause a denial of service (host OS crash)\nor possibly execute arbitrary code in the host OS. (CVE-2017-12188)\n\nIt was discovered that on the PowerPC architecture, the kernel did not\nproperly sanitize the signal stack when handling sigreturn(). A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-1000255)\n\nBo Zhang discovered that the netlink wireless configuration interface in\nthe Linux kernel did not properly validate attributes when handling certain\nrequests. A local attacker with the CAP_NET_ADMIN could use this to cause a\ndenial of service (system crash). (CVE-2017-12153)\n\nIt was discovered that the nested KVM implementation in the Linux kernel in\nsome situations did not properly prevent second level guests from reading\nand writing the hardware CR8 register. A local attacker in a guest could\nuse this to cause a denial of service (system crash). (CVE-2017-12154)\n\nVitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel\ndid not properly track reference counts when merging buffers. A local\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-12190)\n\nIt was discovered that the key management subsystem in the Linux kernel did\nnot properly restrict key reads on negatively instantiated keys. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-12192)\n\nIt was discovered that the ATI Radeon framebuffer driver in the Linux\nkernel did not properly initialize a data structure returned to user space.\nA local attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-14156)\n\nChunYu Wang discovered that the iSCSI transport implementation in the Linux\nkernel did not properly validate data structures. A local attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-14489)\n\nAlexander Potapenko discovered an information leak in the waitid\nimplementation of the Linux kernel. A local attacker could use this to\nexpose sensitive information (kernel memory). (CVE-2017-14954)\n\nIt was discovered that a race condition existed in the ALSA subsystem of\nthe Linux kernel when creating and deleting a port via ioctl(). A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-15265)\n\nDmitry Vyukov discovered that the Floating Point Unit (fpu) subsystem in\nthe Linux kernel did not properly handle attempts to set reserved bits in a\ntask's extended state (xstate) area. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2017-15537)\n\nIt was discovered that a race condition existed in the packet fanout\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-15649)\n\nAndrey Konovalov discovered a use-after-free vulnerability in the USB\nserial console driver in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2017-16525)\n\nAndrey Konovalov discovered that the Ultra Wide Band driver in the Linux\nkernel did not properly check for an error condition. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16526)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel\ncontained a use-after-free vulnerability. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16527)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel did\nnot properly validate USB audio buffer descriptors. A physically proximate\nattacker could use this cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-16529)\n\nAndrey Konovalov discovered that the USB unattached storage driver in the\nLinux kernel contained out-of-bounds error when handling alternative\nsettings. A physically proximate attacker could use to cause a denial of\nservice (system crash) or possibly execute arbitrary code. (CVE-2017-16530)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB interface association descriptors. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16531)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB HID descriptors. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16533)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate CDC metadata. A physically proximate attacker could\nuse this to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-16534)\n","is_hidden":false,"release_packages":{"artful":[{"name":"linux-raspi2","version":"4.13.0-1006.6","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux","version":"4.13.0-17.20","description":"Linux kernel","is_source":true},{"name":"linux-image-4.13.0-17-generic","version":"4.13.0-17.20","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.13.0-17.20"},{"name":"linux-image-generic","version":"4.13.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.13.0-17-lowlatency","version":"4.13.0-17.20","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.13.0-17.20"},{"name":"linux-image-generic-lpae","version":"4.13.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.13.0-1006-raspi2","version":"4.13.0-1006.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.13.0-1006.6"},{"name":"linux-image-4.13.0-17-generic-lpae","version":"4.13.0-17.20","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.13.0-17.20"},{"name":"linux-image-lowlatency","version":"4.13.0.17.18","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-raspi2","version":"4.13.0.1006.4","is_source":false,"source_link":null,"version_link":null}]},"type":"USN","cves_ids":["CVE-2017-1000255","CVE-2017-12153","CVE-2017-12154","CVE-2017-12188","CVE-2017-12190","CVE-2017-12192","CVE-2017-14156","CVE-2017-14489","CVE-2017-14954","CVE-2017-15265","CVE-2017-15537","CVE-2017-15649","CVE-2017-16525","CVE-2017-16526","CVE-2017-16527","CVE-2017-16529","CVE-2017-16530","CVE-2017-16531","CVE-2017-16533","CVE-2017-16534"]},{"id":"USN-3583-2","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-02-23T09:22:33.099388","description":"USN-3583-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu\n12.04 ESM.\n\nIt was discovered that an out-of-bounds write vulnerability existed in the\nFlash-Friendly File System (f2fs) in the Linux kernel. An attacker could\nconstruct a malicious file system that, when mounted, could cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2017-0750)\n\nIt was discovered that a race condition leading to a use-after-free\nvulnerability existed in the ALSA PCM subsystem of the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-0861)\n\nIt was discovered that the KVM implementation in the Linux kernel allowed\npassthrough of the diagnostic I/O port 0x80. An attacker in a guest VM\ncould use this to cause a denial of service (system crash) in the host OS.\n(CVE-2017-1000407)\n\nBo Zhang discovered that the netlink wireless configuration interface in\nthe Linux kernel did not properly validate attributes when handling certain\nrequests. A local attacker with the CAP_NET_ADMIN could use this to cause a\ndenial of service (system crash). (CVE-2017-12153)\n\nVitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel\ndid not properly track reference counts when merging buffers. A local\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-12190)\n\nIt was discovered that the key management subsystem in the Linux kernel did\nnot properly restrict key reads on negatively instantiated keys. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-12192)\n\nIt was discovered that an integer overflow existed in the sysfs interface\nfor the QLogic 24xx+ series SCSI driver in the Linux kernel. A local\nprivileged attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-14051)\n\nOtto Ebeling discovered that the memory manager in the Linux kernel did not\nproperly check the effective UID in some situations. A local attacker could\nuse this to expose sensitive information. (CVE-2017-14140)\n\nIt was discovered that the ATI Radeon framebuffer driver in the Linux\nkernel did not properly initialize a data structure returned to user space.\nA local attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-14156)\n\nChunYu Wang discovered that the iSCSI transport implementation in the Linux\nkernel did not properly validate data structures. A local attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-14489)\n\nJames Patrick-Evans discovered a race condition in the LEGO USB Infrared\nTower driver in the Linux kernel. A physically proximate attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-15102)\n\nChunYu Wang discovered that a use-after-free vulnerability existed in the\nSCTP protocol implementation in the Linux kernel. A local attacker could\nuse this to cause a denial of service (system crash) or possibly execute\narbitrary code, (CVE-2017-15115)\n\nIt was discovered that the key management subsystem in the Linux kernel did\nnot properly handle NULL payloads with non-zero length values. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-15274)\n\nIt was discovered that the Bluebooth Network Encapsulation Protocol (BNEP)\nimplementation in the Linux kernel did not validate the type of socket\npassed in the BNEPCONNADD ioctl(). A local attacker with the CAP_NET_ADMIN\nprivilege could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-15868)\n\nAndrey Konovalov discovered a use-after-free vulnerability in the USB\nserial console driver in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2017-16525)\n\nIt was discovered that the netfilter passive OS fingerprinting (xt_osf)\nmodule did not properly perform access control checks. A local attacker\ncould improperly modify the systemwide OS fingerprint list.\n(CVE-2017-17450)\n\nIt was discovered that the HMAC implementation did not validate the state\nof the underlying cryptographic hash algorithm. A local attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-17806)\n\nDenys Fedoryshchenko discovered a use-after-free vulnerability in the\nnetfilter xt_TCPMSS filter of the Linux kernel. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-18017)\n\nGareth Evans discovered that the shm IPC subsystem in the Linux kernel did\nnot properly restrict mapping page zero. A local privileged attacker could\nuse this to execute arbitrary code. (CVE-2017-5669)\n\nIt was discovered that an integer overflow vulnerability existing in the\nIPv6 implementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (infinite loop). (CVE-2017-7542)\n\nTommi Rantala and Brad Spengler discovered that the memory manager in the\nLinux kernel did not properly enforce the CONFIG_STRICT_DEVMEM protection\nmechanism. A local attacker with access to /dev/mem could use this to\nexpose sensitive information or possibly execute arbitrary code.\n(CVE-2017-7889)\n\nMohamed Ghannam discovered a use-after-free vulnerability in the DCCP\nprotocol implementation in the Linux kernel. A local attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-8824)\n\nMohamed Ghannam discovered a null pointer dereference in the RDS (Reliable\nDatagram Sockets) protocol implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-5333)\n\n范龙飞 discovered that a race condition existed in loop block device\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5344)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-142.191~precise1","description":"Linux hardware enablement kernel from Trusty for Precise ESM","is_source":true},{"name":"linux-image-3.13.0-142-generic","version":"3.13.0-142.191~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-142.191~precise1"},{"name":"linux-image-generic-lpae-lts-trusty","version":"3.13.0.142.133","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-142.191~precise1"},{"name":"linux-image-3.13.0-142-generic-lpae","version":"3.13.0-142.191~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-142.191~precise1"},{"name":"linux-image-generic-lts-trusty","version":"3.13.0.142.133","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-142.191~precise1"}]},"type":"USN","cves_ids":["CVE-2017-0750","CVE-2017-0861","CVE-2017-1000407","CVE-2017-12153","CVE-2017-12190","CVE-2017-12192","CVE-2017-14051","CVE-2017-14140","CVE-2017-14156","CVE-2017-14489","CVE-2017-15102","CVE-2017-15115","CVE-2017-15274","CVE-2017-15868","CVE-2017-16525","CVE-2017-17450","CVE-2017-17806","CVE-2017-18017","CVE-2017-5669","CVE-2017-7542","CVE-2017-7889","CVE-2017-8824","CVE-2018-5333","CVE-2018-5344"]},{"id":"USN-3469-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-10-31T10:25:13.333513","description":"Anthony Perard discovered that the Xen virtual block driver did not\nproperly initialize some data structures before passing them to user space.\nA local attacker in a guest VM could use this to expose sensitive\ninformation from the host OS or other guest VMs. (CVE-2017-10911)\n\nBo Zhang discovered that the netlink wireless configuration interface in\nthe Linux kernel did not properly validate attributes when handling certain\nrequests. A local attacker with the CAP_NET_ADMIN could use this to cause a\ndenial of service (system crash). (CVE-2017-12153)\n\nIt was discovered that the nested KVM implementation in the Linux\nkernel in some situations did not properly prevent second level guests\nfrom reading and writing the hardware CR8 register. A local attacker\nin a guest could use this to cause a denial of service (system crash).\n\nIt was discovered that the key management subsystem in the Linux kernel\ndid not properly restrict key reads on negatively instantiated keys. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-12192)\n\nIt was discovered that an integer overflow existed in the sysfs interface\nfor the QLogic 24xx+ series SCSI driver in the Linux kernel. A local\nprivileged attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-14051)\n\nIt was discovered that the ATI Radeon framebuffer driver in the Linux\nkernel did not properly initialize a data structure returned to user space.\nA local attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-14156)\n\nDave Chinner discovered that the XFS filesystem did not enforce that the\nrealtime inode flag was settable only on filesystems on a realtime device.\nA local attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-14340)\n\nChunYu Wang discovered that the iSCSI transport implementation in the Linux\nkernel did not properly validate data structures. A local attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-14489)\n\nIt was discovered that the generic SCSI driver in the Linux kernel did not\nproperly initialize data returned to user space in some situations. A local\nattacker could use this to expose sensitive information (kernel memory).\n(CVE-2017-14991)\n\nDmitry Vyukov discovered that the Floating Point Unit (fpu) subsystem in\nthe Linux kernel did not properly handle attempts to set reserved bits in a\ntask's extended state (xstate) area. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2017-15537)\n\nPengfei Wang discovered that the Turtle Beach MultiSound audio device\ndriver in the Linux kernel contained race conditions when fetching\nfrom the ring-buffer. A local attacker could use this to cause a\ndenial of service (infinite loop). (CVE-2017-9984, CVE-2017-9985)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-98.121","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.4.0-1039.48","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-gke","version":"4.4.0-1033.33","description":"Linux kernel for Google Container Engine (GKE) systems","is_source":true},{"name":"linux-kvm","version":"4.4.0-1009.14","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1076.84","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1078.83","description":"Linux kernel for Snapdragon processors","is_source":true},{"name":"linux-image-4.4.0-1009-kvm","version":"4.4.0-1009.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1009.14","pocket":"security"},{"name":"linux-image-4.4.0-1033-gke","version":"4.4.0-1033.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-gke","version_link":"https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1033.33","pocket":"security"},{"name":"linux-image-4.4.0-1039-aws","version":"4.4.0-1039.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1039.48","pocket":"security"},{"name":"linux-image-4.4.0-1076-raspi2","version":"4.4.0-1076.84","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1076.84","pocket":"security"},{"name":"linux-image-4.4.0-1078-snapdragon","version":"4.4.0-1078.83","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1078.83","pocket":"security"},{"name":"linux-image-4.4.0-98-generic","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-4.4.0-98-generic-lpae","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-4.4.0-98-lowlatency","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc-e500mc","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc-smp","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc64-emb","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc64-smp","version":"4.4.0-98.121","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"},{"name":"linux-image-extra-4.4.0-1033-gke","version":"4.4.0-1033.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gke","version_link":"https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1033.33","pocket":"security"},{"name":"linux-image-extra-4.4.0-98-generic","version":"4.4.0-98.121","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-98.121","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10911","CVE-2017-12153","CVE-2017-12154","CVE-2017-12192","CVE-2017-14051","CVE-2017-14156","CVE-2017-14340","CVE-2017-14489","CVE-2017-14991","CVE-2017-15537","CVE-2017-9984","CVE-2017-9985"]},{"id":"USN-3469-2","title":"Linux kernel (Xenial HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-10-31T10:29:27.019734","description":"USN-3469-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nAnthony Perard discovered that the Xen virtual block driver did not\nproperly initialize some data structures before passing them to user space.\nA local attacker in a guest VM could use this to expose sensitive\ninformation from the host OS or other guest VMs. (CVE-2017-10911)\n\nBo Zhang discovered that the netlink wireless configuration interface in\nthe Linux kernel did not properly validate attributes when handling certain\nrequests. A local attacker with the CAP_NET_ADMIN could use this to cause a\ndenial of service (system crash). (CVE-2017-12153)\n\nIt was discovered that the nested KVM implementation in the Linux\nkernel in some situations did not properly prevent second level guests\nfrom reading and writing the hardware CR8 register. A local attacker\nin a guest could use this to cause a denial of service (system crash).\n\nIt was discovered that the key management subsystem in the Linux kernel\ndid not properly restrict key reads on negatively instantiated keys. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-12192)\n\nIt was discovered that an integer overflow existed in the sysfs interface\nfor the QLogic 24xx+ series SCSI driver in the Linux kernel. A local\nprivileged attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-14051)\n\nIt was discovered that the ATI Radeon framebuffer driver in the Linux\nkernel did not properly initialize a data structure returned to user space.\nA local attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-14156)\n\nDave Chinner discovered that the XFS filesystem did not enforce that the\nrealtime inode flag was settable only on filesystems on a realtime device.\nA local attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-14340)\n\nChunYu Wang discovered that the iSCSI transport implementation in the Linux\nkernel did not properly validate data structures. A local attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-14489)\n\nIt was discovered that the generic SCSI driver in the Linux kernel did not\nproperly initialize data returned to user space in some situations. A local\nattacker could use this to expose sensitive information (kernel memory).\n(CVE-2017-14991)\n\nDmitry Vyukov discovered that the Floating Point Unit (fpu) subsystem in\nthe Linux kernel did not properly handle attempts to set reserved bits in a\ntask's extended state (xstate) area. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2017-15537)\n\nPengfei Wang discovered that the Turtle Beach MultiSound audio device\ndriver in the Linux kernel contained race conditions when fetching\nfrom the ring-buffer. A local attacker could use this to cause a\ndenial of service (infinite loop). (CVE-2017-9984, CVE-2017-9985)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-xenial","version":"4.4.0-98.121~14.04.1","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-98-generic","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-98-generic-lpae","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-98-lowlatency","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc-e500mc","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc-smp","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc64-emb","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-98-powerpc64-smp","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.4.0-98-generic","version":"4.4.0-98.121~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-98.121~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10911","CVE-2017-12153","CVE-2017-12154","CVE-2017-12192","CVE-2017-14051","CVE-2017-14156","CVE-2017-14340","CVE-2017-14489","CVE-2017-14991","CVE-2017-15537","CVE-2017-9984","CVE-2017-9985"]},{"id":"USN-3583-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-02-23T09:14:24.957484","description":"It was discovered that an out-of-bounds write vulnerability existed in the\nFlash-Friendly File System (f2fs) in the Linux kernel. An attacker could\nconstruct a malicious file system that, when mounted, could cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2017-0750)\n\nIt was discovered that a race condition leading to a use-after-free\nvulnerability existed in the ALSA PCM subsystem of the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-0861)\n\nIt was discovered that the KVM implementation in the Linux kernel allowed\npassthrough of the diagnostic I/O port 0x80. An attacker in a guest VM\ncould use this to cause a denial of service (system crash) in the host OS.\n(CVE-2017-1000407)\n\nBo Zhang discovered that the netlink wireless configuration interface in\nthe Linux kernel did not properly validate attributes when handling certain\nrequests. A local attacker with the CAP_NET_ADMIN could use this to cause a\ndenial of service (system crash). (CVE-2017-12153)\n\nVitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel\ndid not properly track reference counts when merging buffers. A local\nattacker could use this to cause a denial of service (memory exhaustion).\n(CVE-2017-12190)\n\nIt was discovered that the key management subsystem in the Linux kernel did\nnot properly restrict key reads on negatively instantiated keys. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-12192)\n\nIt was discovered that an integer overflow existed in the sysfs interface\nfor the QLogic 24xx+ series SCSI driver in the Linux kernel. A local\nprivileged attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-14051)\n\nOtto Ebeling discovered that the memory manager in the Linux kernel did not\nproperly check the effective UID in some situations. A local attacker could\nuse this to expose sensitive information. (CVE-2017-14140)\n\nIt was discovered that the ATI Radeon framebuffer driver in the Linux\nkernel did not properly initialize a data structure returned to user space.\nA local attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-14156)\n\nChunYu Wang discovered that the iSCSI transport implementation in the Linux\nkernel did not properly validate data structures. A local attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-14489)\n\nJames Patrick-Evans discovered a race condition in the LEGO USB Infrared\nTower driver in the Linux kernel. A physically proximate attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-15102)\n\nChunYu Wang discovered that a use-after-free vulnerability existed in the\nSCTP protocol implementation in the Linux kernel. A local attacker could\nuse this to cause a denial of service (system crash) or possibly execute\narbitrary code, (CVE-2017-15115)\n\nIt was discovered that the key management subsystem in the Linux kernel did\nnot properly handle NULL payloads with non-zero length values. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-15274)\n\nIt was discovered that the Bluebooth Network Encapsulation Protocol (BNEP)\nimplementation in the Linux kernel did not validate the type of socket\npassed in the BNEPCONNADD ioctl(). A local attacker with the CAP_NET_ADMIN\nprivilege could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-15868)\n\nAndrey Konovalov discovered a use-after-free vulnerability in the USB\nserial console driver in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2017-16525)\n\nIt was discovered that the netfilter passive OS fingerprinting (xt_osf)\nmodule did not properly perform access control checks. A local attacker\ncould improperly modify the system-wide OS fingerprint list.\n(CVE-2017-17450)\n\nIt was discovered that the HMAC implementation did not validate the state\nof the underlying cryptographic hash algorithm. A local attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-17806)\n\nDenys Fedoryshchenko discovered a use-after-free vulnerability in the\nnetfilter xt_TCPMSS filter of the Linux kernel. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-18017)\n\nGareth Evans discovered that the shm IPC subsystem in the Linux kernel did\nnot properly restrict mapping page zero. A local privileged attacker could\nuse this to execute arbitrary code. (CVE-2017-5669)\n\nIt was discovered that an integer overflow vulnerability existing in the\nIPv6 implementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (infinite loop). (CVE-2017-7542)\n\nTommi Rantala and Brad Spengler discovered that the memory manager in the\nLinux kernel did not properly enforce the CONFIG_STRICT_DEVMEM protection\nmechanism. A local attacker with access to /dev/mem could use this to\nexpose sensitive information or possibly execute arbitrary code.\n(CVE-2017-7889)\n\nMohamed Ghannam discovered a use-after-free vulnerability in the DCCP\nprotocol implementation in the Linux kernel. A local attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-8824)\n\nMohamed Ghannam discovered a null pointer dereference in the RDS (Reliable\nDatagram Sockets) protocol implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-5333)\n\n范龙飞 discovered that a race condition existed in loop block device\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5344)\n\nUSN-3524-1 mitigated CVE-2017-5754 (Meltdown) for the amd64\narchitecture in Ubuntu 14.04 LTS. This update provides the\ncorresponding mitigations for the ppc64el architecture. Original\nadvisory details:\n\n Jann Horn discovered that microprocessors utilizing speculative execution\n and indirect branch prediction may allow unauthorized memory reads via\n sidechannel attacks. This flaw is known as Meltdown. A local attacker could\n use this to expose sensitive information, including kernel memory.\n (CVE-2017-5754)\n\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-142.191","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-142-generic","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-generic-lpae","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-lowlatency","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-powerpc-e500","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-powerpc-e500mc","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-powerpc-smp","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-powerpc64-emb","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-3.13.0-142-powerpc64-smp","version":"3.13.0-142.191","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"},{"name":"linux-image-extra-3.13.0-142-generic","version":"3.13.0-142.191","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-142.191","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-0750","CVE-2017-0861","CVE-2017-1000407","CVE-2017-12153","CVE-2017-12190","CVE-2017-12192","CVE-2017-14051","CVE-2017-14140","CVE-2017-14156","CVE-2017-14489","CVE-2017-15102","CVE-2017-15115","CVE-2017-15274","CVE-2017-15868","CVE-2017-16525","CVE-2017-17450","CVE-2017-17806","CVE-2017-18017","CVE-2017-5669","CVE-2017-5754","CVE-2017-7542","CVE-2017-7889","CVE-2017-8824","CVE-2018-5333","CVE-2018-5344"]}]},{"id":"CVE-2017-14623","published":"2017-09-20T23:29:00","updated_at":"2025-08-26T11:58:03.980787+00:00","description":"\nIn the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may\nbe able to login with an empty password. This issue affects an application\nusing this package if these conditions are met: (1) it relies only on the\nreturn error of the Bind function call to determine whether a user is\nauthorized (i.e., a nil return value is interpreted as successful\nauthorization) and (2) it is used with an LDAP server allowing\nunauthenticated bind.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/go-ldap/ldap/pull/126","https://github.com/go-ldap/ldap/commit/95ede1266b237bf8e9aa5dce0b3250e51bfefe66","https://www.cve.org/CVERecord?id=CVE-2017-14623"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876404"],"patches":{"golang-github-go-ldap-ldap":[]},"tags":{},"packages":[{"name":"golang-github-go-ldap-ldap","source":"https://ubuntu.com/security/cve?package=golang-github-go-ldap-ldap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-ldap-ldap","debian":"https://tracker.debian.org/pkg/golang-github-go-ldap-ldap","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.1-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.5.1-4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-14610","published":"2017-09-20T18:29:00","updated_at":"2025-08-26T11:58:03.980787+00:00","description":"\nbareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and\nearlier create a PID file after dropping privileges to a non-root account,\nwhich might allow local users to kill arbitrary processes by leveraging\naccess to this non-root account for PID file modification before a root\nscript executes a \"kill `cat /pathname`\" command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.bareos.org/view.php?id=847","https://www.cve.org/CVERecord?id=CVE-2017-14610"],"bugs":[""],"patches":{"bareos":[]},"tags":{},"packages":[{"name":"bareos","source":"https://ubuntu.com/security/cve?package=bareos","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bareos","debian":"https://tracker.debian.org/pkg/bareos","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-14609","published":"2017-09-20T18:29:00","updated_at":"2025-07-11T07:38:52.253002+00:00","description":"\nThe server daemons in Kannel 1.5.0 and earlier create a PID file after\ndropping privileges to a non-root account, which might allow local users to\nkill arbitrary processes by leveraging access to this non-root account for\nPID file modification before a root script executes a \"kill `cat\n/pathname`\" command, as demonstrated by bearerbox.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://redmine.kannel.org/issues/771","https://www.cve.org/CVERecord?id=CVE-2017-14609"],"bugs":[""],"patches":{"kannel":[]},"tags":{},"packages":[{"name":"kannel","source":"https://ubuntu.com/security/cve?package=kannel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kannel","debian":"https://tracker.debian.org/pkg/kannel","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-6673","published":"2017-09-20T18:29:00","updated_at":"2025-08-25T21:43:54.773334+00:00","description":"\nUse-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/08/19/14","https://sourceforge.net/p/libpgf/code/147/","https://sourceforge.net/p/libpgf/code/148/","https://ubuntu.com/security/notices/USN-4554-1","https://www.cve.org/CVERecord?id=CVE-2015-6673"],"bugs":[""],"patches":{"libpgf":["upstream: https://sourceforge.net/p/libpgf/code/147/","upstream: https://sourceforge.net/p/libpgf/code/148/"]},"tags":{},"packages":[{"name":"libpgf","source":"https://ubuntu.com/security/cve?package=libpgf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpgf","debian":"https://tracker.debian.org/pkg/libpgf","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"6.14.12-3.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"6.14.12-3.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"6.14.12-3.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"6.14.12-3.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"6.14.12-3.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.14.12-3.2","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"6.14.12-3.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-4554-1"],"notices":[{"id":"USN-4554-1","title":"libPGF vulnerability","summary":"libPGF could be made to crash if it opened a specially crafted\nfile.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-28T18:50:35.194603","description":"It was discovered that libPGF lacked proper validation when opening a\nspecially crafted PGF file. An attacker could possibly use this issue to\ncause a denial of service.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libpgf","version":"6.14.12-3.1ubuntu0.1","description":"Progressive Graphics File (PGF) library","is_source":true},{"name":"libpgf-dev","version":"6.14.12-3.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpgf","version_link":"https://launchpad.net/ubuntu/+source/libpgf/6.14.12-3.1ubuntu0.1","pocket":"security"},{"name":"libpgf6","version":"6.14.12-3.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpgf","version_link":"https://launchpad.net/ubuntu/+source/libpgf/6.14.12-3.1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-6673"]}]},{"id":"CVE-2015-5395","published":"2017-09-20T18:29:00","updated_at":"2025-08-26T11:53:04.777261+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/07/07/10","http://www.sogo.nu/bugs/view.php?id=3246","https://www.cve.org/CVERecord?id=CVE-2015-5395"],"bugs":[""],"patches":{"sogo":[]},"tags":{},"packages":[{"name":"sogo","source":"https://ubuntu.com/security/cve?package=sogo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sogo","debian":"https://tracker.debian.org/pkg/sogo","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4-0.2","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.2.10-1build1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"5.10.0-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"5.10.0-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"5.10.0-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5.10.0-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-4707","published":"2017-09-20T18:29:00","updated_at":"2025-08-25T21:40:18.957718+00:00","description":"\nCross-site scripting (XSS) vulnerability in IPython before 3.2 allows\nremote attackers to inject arbitrary web script or HTML via vectors\ninvolving JSON error messages and the /api/notebooks path.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"It isn't clear if iPython versions less than 2.0 are affected"},{"author":"debian","note":"Problematic code introduced in rel-2.0.0"}],"codename":null,"priority":"low","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/06/22/4","https://www.cve.org/CVERecord?id=CVE-2015-4707"],"bugs":[""],"patches":{"ipython":[]},"tags":{},"packages":[{"name":"ipython","source":"https://ubuntu.com/security/cve?package=ipython","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ipython","debian":"https://tracker.debian.org/pkg/ipython","statuses":[{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.4.1-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-2927","published":"2017-09-20T18:29:00","updated_at":"2025-08-25T21:37:05.274606+00:00","description":"\nnode 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a\ndenial of service (bandwidth consumption).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/04/03/10","https://www.cve.org/CVERecord?id=CVE-2015-2927"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777013"],"patches":{"node":[]},"tags":{},"packages":[{"name":"node","source":"https://ubuntu.com/security/cve?package=node","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node","debian":"https://tracker.debian.org/pkg/node","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-1865","published":"2017-09-20T18:29:00","updated_at":"2025-08-07T17:17:38.820028+00:00","description":"\nfts.c in coreutils 8.4 allows local users to delete arbitrary files.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"8.13 is not affected"}],"codename":null,"priority":"low","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-1865"],"bugs":[""],"patches":{"coreutils":[]},"tags":{},"packages":[{"name":"coreutils","source":"https://ubuntu.com/security/cve?package=coreutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=coreutils","debian":"https://tracker.debian.org/pkg/coreutils","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"8.13-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9804","published":"2017-09-20T17:29:00","updated_at":"2025-08-25T22:42:09.396363+00:00","description":"\nIn Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an\napplication allows entering a URL in a form field and built-in URLValidator\nis used, it is possible to prepare a special URL which will be used to\noverload server process when performing validation of the URL. NOTE: this\nvulnerability exists because of an incomplete fix for S2-047 /\nCVE-2017-7672.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://struts.apache.org/docs/s2-050.html","https://www.cve.org/CVERecord?id=CVE-2017-9804"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9793","published":"2017-09-20T17:29:00","updated_at":"2025-08-25T22:42:09.396363+00:00","description":"\nThe REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5\nthrough 2.5.12 is using an outdated XStream library which is vulnerable and\nallow perform a DoS attack using malicious request with specially crafted\nXML payload.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://struts.apache.org/docs/s2-051.html","https://www.cve.org/CVERecord?id=CVE-2017-9793"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was not-affected [code not present]]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12611","published":"2017-09-20T17:29:00","updated_at":"2025-08-25T22:22:21.165537+00:00","description":"\nIn Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an\nunintentional expression in a Freemarker tag instead of string literals can\nlead to a RCE attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://struts.apache.org/docs/s2-053.html","https://www.cve.org/CVERecord?id=CVE-2017-12611"],"bugs":[""],"patches":{"libstruts1.2-java":[]},"tags":{},"packages":[{"name":"libstruts1.2-java","source":"https://ubuntu.com/security/cve?package=libstruts1.2-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libstruts1.2-java","debian":"https://tracker.debian.org/pkg/libstruts1.2-java","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":55320,"limit":20,"total_results":79316}