{"cves":[{"id":"CVE-2017-6419","published":"2017-08-06T00:00:00","updated_at":"2025-10-01T23:17:08.746663+00:00","description":"\nmspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows\nremote attackers to cause a denial of service (heap-based buffer overflow\nand application crash) or possibly have unspecified other impact via a\ncrafted CHM file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"clamav in xenial+ uses the system libmspack, trusty uses\nthe embedded one."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clamav_chm_crash.md","https://ubuntu.com/security/notices/USN-3394-1","https://ubuntu.com/security/notices/USN-3393-1","https://ubuntu.com/security/notices/USN-3393-2","https://www.cve.org/CVERecord?id=CVE-2017-6419","https://ubuntu.com/security/notices/USN-7788-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871263","https://bugzilla.clamav.net/show_bug.cgi?id=11701 (private)"],"patches":{"clamav":["upstream: https://github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1"],"libmspack":["upstream: https://github.com/kyz/libmspack/commit/6139a0b9e93fcb7fcf423e56aa825bc869e02229"]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"artful","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.99.2+addedllvm-0ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"uses system libmspack","component":null,"pocket":"security"}]},{"name":"libmspack","source":"https://ubuntu.com/security/cve?package=libmspack","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libmspack","debian":"https://tracker.debian.org/pkg/libmspack","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.5-1ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.5-1ubuntu0.17.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.6-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.4-1ubuntu0.1~esm2","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-3393-2","USN-3393-1","USN-3394-1","USN-7788-1"],"notices":[{"id":"USN-3393-2","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-08-17T19:11:33.916763","description":"USN-3393-1 fixed several vulnerabilities in ClamAV. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that ClamAV incorrectly handled parsing certain e-mail\n messages. A remote attacker could possibly use this issue to cause ClamAV\n to crash, resulting in a denial of service. (CVE-2017-6418)\n \n It was discovered that ClamAV incorrectly handled certain malformed CHM\n files. A remote attacker could use this issue to cause ClamAV to crash,\n resulting in a denial of service, or possibly execute arbitrary code. This\n issue only affected Ubuntu 14.04 LTS. In the default installation,\n attackers would be isolated by the ClamAV AppArmor profile. (CVE-2017-6419)\n \n It was discovered that ClamAV incorrectly handled parsing certain PE files\n with WWPack compression. A remote attacker could possibly use this issue to\n cause ClamAV to crash, resulting in a denial of service. (CVE-2017-6420)\n","is_hidden":false,"release_packages":{"precise":[{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.12.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.12.04.2"}]},"type":"USN","cves_ids":["CVE-2017-6418","CVE-2017-6419","CVE-2017-6420"]},{"id":"USN-3393-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-08-17T16:58:06.640599","description":"It was discovered that ClamAV incorrectly handled parsing certain e-mail\nmessages. A remote attacker could possibly use this issue to cause ClamAV\nto crash, resulting in a denial of service. (CVE-2017-6418)\n\nIt was discovered that ClamAV incorrectly handled certain malformed CHM\nfiles. A remote attacker could use this issue to cause ClamAV to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS. In the default installation,\nattackers would be isolated by the ClamAV AppArmor profile. (CVE-2017-6419)\n\nIt was discovered that ClamAV incorrectly handled parsing certain PE files\nwith WWPack compression. A remote attacker could possibly use this issue to\ncause ClamAV to crash, resulting in a denial of service. (CVE-2017-6420)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-base","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-daemon","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-docs","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-milter","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"libclamav-dev","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"libclamav7","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"}],"xenial":[{"name":"clamav","version":"0.99.2+dfsg-0ubuntu0.16.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-base","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-daemon","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-docs","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-milter","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamdscan","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"libclamav-dev","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"libclamav7","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"clamav","version":"0.99.2+dfsg-6ubuntu0.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+dfsg-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-6ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-6418","CVE-2017-6419","CVE-2017-6420"]},{"id":"USN-3394-1","title":"libmspack vulnerabilities","summary":"Several security issues were fixed in libmspack.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-08-17T17:03:49.142502","description":"It was discovered that libmspack incorrectly handled certain malformed CHM\nfiles. A remote attacker could use this issue to cause libmspack to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2017-6419)\n\nIt was discovered that libmspack incorrectly handled certain malformed CAB\nfiles. A remote attacker could use this issue to cause libmspack to crash,\nresulting in a denial of service. (CVE-2017-6419)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"libmspack","version":"0.5-1ubuntu0.16.04.1","description":"library for Microsoft compression formats","is_source":true},{"name":"libmspack-dev","version":"0.5-1ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":"https://launchpad.net/ubuntu/+source/libmspack/0.5-1ubuntu0.16.04.1","pocket":"security"},{"name":"libmspack-doc","version":"0.5-1ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":"https://launchpad.net/ubuntu/+source/libmspack/0.5-1ubuntu0.16.04.1","pocket":"security"},{"name":"libmspack0","version":"0.5-1ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":"https://launchpad.net/ubuntu/+source/libmspack/0.5-1ubuntu0.16.04.1","pocket":"security"}],"zesty":[{"name":"libmspack","version":"0.5-1ubuntu0.17.04.1","description":"library for Microsoft compression formats","is_source":true},{"name":"libmspack0","version":"0.5-1ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":"https://launchpad.net/ubuntu/+source/libmspack/0.5-1ubuntu0.17.04.1"}]},"type":"USN","cves_ids":["CVE-2017-11423","CVE-2017-6419"]},{"id":"USN-7788-1","title":"libmspack vulnerabilities","summary":"Several security issues were fixed in libmspack.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-10-01T00:06:41.235654","description":"Jakub Wilk discovered that libmspack did not correctly handle certain\ninteger operations and bounds checking. A remote attacker could possibly\nuse this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,\nCVE-2015-4469, CVE-2015-4472)\n\nIt was discovered that libmspack incorrectly handled certain malformed CAB\nfiles. A remote attacker could use this issue to cause libmspack to crash,\nresulting in a denial of service. (CVE-2017-11423)\n\nIt was discovered that libmspack incorrectly handled certain malformed CHM\nfiles. A remote attacker could use this issue to cause libmspack to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2017-6419)\n\nHanno Böck discovered that libmspack incorrectly handled certain CHM files.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2018-14679, CVE-2018-14680)\n\nJakub Wilk discovered that libmspack incorrectly handled certain KWAJ\nfiles. An attacker could possibly use this issue to execute arbitrary code.\n(CVE-2018-14681)\n\nDmitry Glavatskikh discovered that libmspack incorrectly handled certain\nCHM files. An attacker could possibly use this issue to execute arbitrary\ncode. (CVE-2018-14682)\n\nIt was discovered libmspack incorrectly handled certain malformed CAB\nfiles. A remote attacker could use this issue to cause libmspack to crash,\nresulting in a denial of service. (CVE-2018-18585)\n\nIt was discovered that libmspack incorrectly handled certain CHM files. A\nremote attacker could possibly use this issue to access sensitive\ninformation. (CVE-2019-1010305)","is_hidden":false,"release_packages":{"trusty":[{"name":"libmspack","version":"0.4-1ubuntu0.1~esm2","description":"library for Microsoft compression formats","is_source":true},{"name":"libmspack-dev","version":"0.4-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmspack-doc","version":"0.4-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmspack0","version":"0.4-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libmspack","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2018-14679","CVE-2018-14681","CVE-2015-4468","CVE-2018-14682","CVE-2017-6419","CVE-2015-4469","CVE-2018-18585","CVE-2018-14680","CVE-2019-1010305","CVE-2015-4472","CVE-2015-4467","CVE-2017-11423"]}]},{"id":"CVE-2017-6418","published":"2017-08-06T00:00:00","updated_at":"2025-08-25T22:36:11.656966+00:00","description":"\nlibclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a\ndenial of service (out-of-bounds read) via a crafted e-mail message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/varsleak/varsleak-vul/blob/master/clamav-vul/heap-overflow/clamav_email_crash.md","https://ubuntu.com/security/notices/USN-3393-1","https://ubuntu.com/security/notices/USN-3393-2","https://www.cve.org/CVERecord?id=CVE-2017-6418"],"bugs":["https://bugzilla.clamav.net/show_bug.cgi?id=11797 (private)"],"patches":{"clamav":["upstream: https://github.com/vrtadmin/clamav-devel/commit/586a5180287262070637c8943f2f7efd652e4a2c"]},"tags":{},"packages":[{"name":"clamav","source":"https://ubuntu.com/security/cve?package=clamav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=clamav","debian":"https://tracker.debian.org/pkg/clamav","statuses":[{"release_codename":"trusty","status":"released","description":"0.99.2+addedllvm-0ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.99.3~beta1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.99.2+dfsg-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.99.2+dfsg-6ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3393-2","USN-3393-1"],"notices":[{"id":"USN-3393-2","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-08-17T19:11:33.916763","description":"USN-3393-1 fixed several vulnerabilities in ClamAV. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that ClamAV incorrectly handled parsing certain e-mail\n messages. A remote attacker could possibly use this issue to cause ClamAV\n to crash, resulting in a denial of service. (CVE-2017-6418)\n \n It was discovered that ClamAV incorrectly handled certain malformed CHM\n files. A remote attacker could use this issue to cause ClamAV to crash,\n resulting in a denial of service, or possibly execute arbitrary code. This\n issue only affected Ubuntu 14.04 LTS. In the default installation,\n attackers would be isolated by the ClamAV AppArmor profile. (CVE-2017-6419)\n \n It was discovered that ClamAV incorrectly handled parsing certain PE files\n with WWPack compression. A remote attacker could possibly use this issue to\n cause ClamAV to crash, resulting in a denial of service. (CVE-2017-6420)\n","is_hidden":false,"release_packages":{"precise":[{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.12.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.12.04.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.12.04.2"}]},"type":"USN","cves_ids":["CVE-2017-6418","CVE-2017-6419","CVE-2017-6420"]},{"id":"USN-3393-1","title":"ClamAV vulnerabilities","summary":"Several security issues were fixed in ClamAV.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-08-17T16:58:06.640599","description":"It was discovered that ClamAV incorrectly handled parsing certain e-mail\nmessages. A remote attacker could possibly use this issue to cause ClamAV\nto crash, resulting in a denial of service. (CVE-2017-6418)\n\nIt was discovered that ClamAV incorrectly handled certain malformed CHM\nfiles. A remote attacker could use this issue to cause ClamAV to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS. In the default installation,\nattackers would be isolated by the ClamAV AppArmor profile. (CVE-2017-6419)\n\nIt was discovered that ClamAV incorrectly handled parsing certain PE files\nwith WWPack compression. A remote attacker could possibly use this issue to\ncause ClamAV to crash, resulting in a denial of service. (CVE-2017-6420)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-base","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-daemon","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-docs","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-milter","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"libclamav-dev","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"},{"name":"libclamav7","version":"0.99.2+addedllvm-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+addedllvm-0ubuntu0.14.04.2","pocket":"security"}],"xenial":[{"name":"clamav","version":"0.99.2+dfsg-0ubuntu0.16.04.2","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-base","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-daemon","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-docs","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-freshclam","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-milter","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamav-testfiles","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"clamdscan","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"libclamav-dev","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"},{"name":"libclamav7","version":"0.99.2+dfsg-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-0ubuntu0.16.04.2","pocket":"security"}],"zesty":[{"name":"clamav","version":"0.99.2+dfsg-6ubuntu0.1","description":"Anti-virus utility for Unix","is_source":true},{"name":"clamav","version":"0.99.2+dfsg-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/clamav","version_link":"https://launchpad.net/ubuntu/+source/clamav/0.99.2+dfsg-6ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-6418","CVE-2017-6419","CVE-2017-6420"]}]},{"id":"CVE-2017-12587","published":"2017-08-06T00:00:00","updated_at":"2025-08-25T22:22:11.141374+00:00","description":"\nImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage\nfunction in coders\\pwp.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"0142-Avoid-unbounded-loop-in-pwp-coder.patch in unstable\n0098-Avoid-unbounded-loop-in-pwp-coder.patchin stretch\n0276-CVE-2017-12587-Fix-large-loop-vulnerability-in-ReadPWPImage.patch in wheezy"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-12587"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/535","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870526"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/d4192df5eb03892089806d52a317cc3101856726"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-12566","published":"2017-08-05T18:29:00","updated_at":"2025-08-25T22:22:11.141374+00:00","description":"\nIn ImageMagick 7.0.6-2, a memory leak vulnerability was found in the\nfunction ReadMVGImage in coders/mvg.c, which allows attackers to cause a\ndenial of service, related to the function ReadSVGImage in svg.c.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"0137-memory-leak-in-ReadSVGImage.patch in unstable\n0275-CVE-2017-12566-Fix-memory-leak-in-ReadMVGImage.patch in wheezy\nnot fixing memory leak in trusty and xenial"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-12566"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/603","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870503"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/27b3b9ca5cfb7b8935852cf315abc005ea7c1e16"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12565","published":"2017-08-05T18:29:00","updated_at":"2025-08-25T22:22:11.141374+00:00","description":"\nIn ImageMagick 7.0.6-2, a memory leak vulnerability was found in the\nfunction ReadOneJNGImage in coders/png.c, which allows attackers to cause a\ndenial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"0120-memory-leak-in-ReadOneJNGImage-upstream-602.patch in unstable\n0274-CVE-2017-12565-Fix-memory-leak-in-ReadOneJNGImage.patch in wheezy\nnot fixing memory leak in trusty and xenial"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-12565"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/602","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870115"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/4d0ac66c9778faebd2d1fac7140462b043626458"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12564","published":"2017-08-05T18:29:00","updated_at":"2025-08-25T22:22:11.141374+00:00","description":"\nIn ImageMagick 7.0.6-2, a memory leak vulnerability was found in the\nfunction ReadMATImage in coders/mat.c, which allows attackers to cause a\ndenial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"0106-Memory-leak-in-mat-coder.patch in unstable\n0272-CVE-2017-12564-Fix-memory-leak-in-ReadMATImage.patch in wheezy\nnot fixing memory leak in trusty and xenial"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-12564"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/601","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870017"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/a4779cfbee2e4235fa9f9f8f2e58dca17f7ccc6b"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12562","published":"2017-08-05T17:29:00","updated_at":"2025-08-25T22:22:06.075129+00:00","description":"\nHeap-based Buffer Overflow in the psf_binheader_writef function in common.c\nin libsndfile through 1.0.28 allows remote attackers to cause a denial of\nservice (application crash) or possibly have unspecified other impact.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian's patch in 1.0.28-3 doesn't match the upsteam patch.\nneed to investigate further, looks like parts are missing.\n\nreproducer in upstream bug report."}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4704-1","https://www.cve.org/CVERecord?id=CVE-2017-12562"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=869166","https://github.com/erikd/libsndfile/issues/292"],"patches":{"libsndfile":["upstream: https://github.com/erikd/libsndfile/commit/cf7a8182c2642c50f1cf90dddea9ce96a8bad2e8"]},"tags":{},"packages":[{"name":"libsndfile","source":"https://ubuntu.com/security/cve?package=libsndfile","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsndfile","debian":"https://tracker.debian.org/pkg/libsndfile","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.0.25-7ubuntu2.2+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.0.28-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.0.25-10ubuntu0.16.04.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.0.28-3","component":null,"pocket":"security"}]}],"notices_ids":["USN-4704-1"],"notices":[{"id":"USN-4704-1","title":"libsndfile vulnerabilities","summary":"Several security issues were fixed in libsndfile.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2021-01-26T16:23:13.203532","description":"It was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-12562)\n\nIt was discovered that libsndfile incorrectly handled certain malformed\nfiles. A remote attacker could use this issue to cause libsndfile to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 ESM. (CVE-2017-14245,\nCVE-2017-14246, CVE-2017-14634, CVE-2017-16942, CVE-2017-6892,\nCVE-2018-13139, CVE-2018-19432, CVE-2018-19661, CVE-2018-19662,\nCVE-2018-19758, CVE-2019-3832)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libsndfile","version":"1.0.25-7ubuntu2.2+esm1","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"libsndfile1-dev","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"},{"name":"sndfile-programs","version":"1.0.25-7ubuntu2.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libsndfile","version":"1.0.25-10ubuntu0.16.04.3","description":"Library for reading/writing audio files","is_source":true},{"name":"libsndfile1","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"libsndfile1-dev","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"},{"name":"sndfile-programs","version":"1.0.25-10ubuntu0.16.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libsndfile","version_link":"https://launchpad.net/ubuntu/+source/libsndfile/1.0.25-10ubuntu0.16.04.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-12562","CVE-2018-19758","CVE-2018-19661","CVE-2017-16942","CVE-2017-6892","CVE-2018-19432","CVE-2018-19662","CVE-2017-14246","CVE-2017-14634","CVE-2019-3832","CVE-2018-13139","CVE-2017-14245"]}]},{"id":"CVE-2017-12563","published":"2017-08-05T00:00:00","updated_at":"2025-08-25T22:22:11.141374+00:00","description":"\nIn ImageMagick 7.0.6-2, a memory exhaustion vulnerability was found in the\nfunction ReadPSDImage in coders/psd.c, which allows attackers to cause a\ndenial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"0144-memory-exhaustion-in-ReadPSDImage.patch in unstable\n0271-CVE-2017-12563-Fix-memory-exhaustion-in-ReadPSDImage.patch in wheezy"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3681-1","https://www.cve.org/CVERecord?id=CVE-2017-12563"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/599","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870530"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/7d3af83d8b946f952bfd028451e6dfb1f7ace07a"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8:6.9.7.4+dfsg-16ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.11","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3681-1"],"notices":[{"id":"USN-3681-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-12T11:40:14.599634","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"artful":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu2.2"}],"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-16ubuntu6.2","pocket":"security"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.11","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.11","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-1000445","CVE-2017-1000476","CVE-2017-10995","CVE-2017-11352","CVE-2017-11533","CVE-2017-11535","CVE-2017-11537","CVE-2017-11639","CVE-2017-11640","CVE-2017-12140","CVE-2017-12418","CVE-2017-12429","CVE-2017-12430","CVE-2017-12431","CVE-2017-12432","CVE-2017-12433","CVE-2017-12435","CVE-2017-12563","CVE-2017-12587","CVE-2017-12640","CVE-2017-12643","CVE-2017-12644","CVE-2017-12670","CVE-2017-12674","CVE-2017-12691","CVE-2017-12692","CVE-2017-12693","CVE-2017-12875","CVE-2017-12877","CVE-2017-12983","CVE-2017-13058","CVE-2017-13059","CVE-2017-13060","CVE-2017-13061","CVE-2017-13062","CVE-2017-13131","CVE-2017-13134","CVE-2017-13139","CVE-2017-13142","CVE-2017-13143","CVE-2017-13144","CVE-2017-13145","CVE-2017-13758","CVE-2017-13768","CVE-2017-13769","CVE-2017-14060","CVE-2017-14172","CVE-2017-14173","CVE-2017-14174","CVE-2017-14175","CVE-2017-14224","CVE-2017-14249","CVE-2017-14325","CVE-2017-14326","CVE-2017-14341","CVE-2017-14342","CVE-2017-14343","CVE-2017-14400","CVE-2017-14505","CVE-2017-14531","CVE-2017-14532","CVE-2017-14533","CVE-2017-14607","CVE-2017-14624","CVE-2017-14625","CVE-2017-14626","CVE-2017-14682","CVE-2017-14684","CVE-2017-14739","CVE-2017-14741","CVE-2017-14989","CVE-2017-15015","CVE-2017-15016","CVE-2017-15017","CVE-2017-15032","CVE-2017-15033","CVE-2017-15217","CVE-2017-15218","CVE-2017-15277","CVE-2017-15281","CVE-2017-16546","CVE-2017-17499","CVE-2017-17504","CVE-2017-17680","CVE-2017-17681","CVE-2017-17682","CVE-2017-17879","CVE-2017-17881","CVE-2017-17882","CVE-2017-17884","CVE-2017-17885","CVE-2017-17886","CVE-2017-17887","CVE-2017-17914","CVE-2017-17934","CVE-2017-18008","CVE-2017-18022","CVE-2017-18027","CVE-2017-18028","CVE-2017-18029","CVE-2017-18209","CVE-2017-18211","CVE-2017-18251","CVE-2017-18252","CVE-2017-18254","CVE-2017-18271","CVE-2017-18273","CVE-2018-10177","CVE-2018-10804","CVE-2018-10805","CVE-2018-11251","CVE-2018-11625","CVE-2018-11655","CVE-2018-11656","CVE-2018-5246","CVE-2018-5247","CVE-2018-5248","CVE-2018-5357","CVE-2018-5358","CVE-2018-6405","CVE-2018-7443","CVE-2018-8804","CVE-2018-8960","CVE-2018-9133"]}]},{"id":"CVE-2017-12482","published":"2017-08-04T19:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe ledger::parse_date_mask_routine function in times.cc in Ledger 3.1.1\nallows remote attackers to cause a denial of service (stack-based buffer\noverflow and application crash) or possibly have unspecified other impact\nvia a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://bugs.ledger-cli.org/show_bug.cgi?id=1224","https://github.com/ledger/ledger/commit/7c0ae5b02571e21f97d45f5d091cb78af9885713","https://www.cve.org/CVERecord?id=CVE-2017-12482"],"bugs":[""],"patches":{"ledger":[]},"tags":{},"packages":[{"name":"ledger","source":"https://ubuntu.com/security/cve?package=ledger","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ledger","debian":"https://tracker.debian.org/pkg/ledger","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12481","published":"2017-08-04T19:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe find_option function in option.cc in Ledger 3.1.1 allows remote\nattackers to cause a denial of service (stack-based buffer overflow and\napplication crash) or possibly have unspecified other impact via a crafted\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://bugs.ledger-cli.org/show_bug.cgi?id=1222","https://github.com/ledger/ledger/commit/c5343f18744d0f6fddcc590f9a54c23674d8c489","https://www.cve.org/CVERecord?id=CVE-2017-12481"],"bugs":[""],"patches":{"ledger":[]},"tags":{},"packages":[{"name":"ledger","source":"https://ubuntu.com/security/cve?package=ledger","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ledger","debian":"https://tracker.debian.org/pkg/ledger","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.1.2+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-12459","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary\nFile Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils\n2.29 and earlier, allows remote attackers to cause an out of bounds heap\nwrite and possibly achieve code execution via a crafted mach-o file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commit as CVE-2017-12455"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21840","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12459"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8bdf0be19d2777565a8b1c88347f65d6a4b8c5fc","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=796337aa8ba0aa0397c07c264f82fe8eb9fd46e0"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12458","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary\nFile Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils\n2.29 and earlier, allows remote attackers to cause an out of bounds heap\nread via a crafted nlm file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commit as CVE-2017-12455"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21840","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12458"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8bdf0be19d2777565a8b1c88347f65d6a4b8c5fc","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=796337aa8ba0aa0397c07c264f82fe8eb9fd46e0"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12457","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe bfd_make_section_with_flags function in section.c in the Binary File\nDescriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29\nand earlier, allows remote attackers to cause a NULL dereference via a\ncrafted file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commit as CVE-2017-12455"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21840","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12457"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8bdf0be19d2777565a8b1c88347f65d6a4b8c5fc","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=796337aa8ba0aa0397c07c264f82fe8eb9fd46e0"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12456","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils\n2.29 and earlier allows remote attackers to cause an out of bounds heap\nread via a crafted binary file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commits as CVE-2017-12450"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21813","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12456"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12455","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe evax_bfd_print_emh function in vms-alpha.c in the Binary File\nDescriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29\nand earlier, allows remote attackers to cause an out of bounds heap read\nvia a crafted vms alpha file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same commit as CVE-2017-12449"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21840","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12455"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8bdf0be19d2777565a8b1c88347f65d6a4b8c5fc","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=796337aa8ba0aa0397c07c264f82fe8eb9fd46e0"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12454","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File\nDescriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29\nand earlier, allows remote attackers to cause an arbitrary memory read via\na crafted vms alpha file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commits as CVE-2017-12450"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21813","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12454"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12453","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor\n(BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and\nearlier, allows remote attackers to cause an out of bounds heap read via a\ncrafted vms alpha file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commits as CVE-2017-12450"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21813","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12453"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12452","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in\nthe Binary File Descriptor (BFD) library (aka libbfd), as distributed in\nGNU Binutils 2.29 and earlier, allows remote attackers to cause an out of\nbounds heap read via a crafted mach-o file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"same commits as CVE-2017-12450"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21813","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12452"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12451","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and\nbfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka\nlibbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote\nattackers to cause an out of bounds stack read via a crafted COFF image\nfile.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21786","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12451"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=29866fa186ee3ebda5242221607dba360b2e541e","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=6c4e7b6bfbc4679f695106de2817ecf02b27c8be","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=7e693dd5cede637daf4456a2a8f207be1044c6e8"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]},{"id":"CVE-2017-12450","published":"2017-08-04T15:29:00","updated_at":"2025-08-26T11:57:32.241291+00:00","description":"\nThe alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File\nDescriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29\nand earlier, allows remote attackers to cause an out of bounds heap write\nand possibly achieve code execution via a crafted vms alpha file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reproducers attached to bug report"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceware.org/bugzilla/show_bug.cgi?id=21813","https://ubuntu.com/security/notices/USN-4336-2","https://www.cve.org/CVERecord?id=CVE-2017-12450"],"bugs":[""],"patches":{"binutils":["other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=ca4cf9b9c622a5695e01f7f5815a7382a31fcf51","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=8a2df5e2df374289e00ecd8f099eb46d76ef982e","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=deeb3d27c254ad8bf8c3877fa6b61817f56191f5","other: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=patch;h=64aa1246572306b72dc479b46d13ff749b0c3236"]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"xenial","status":"released","description":"2.26.1-1ubuntu1~16.04.8+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"groovy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.29.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.29.1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-4336-2"],"notices":[{"id":"USN-4336-2","title":"GNU binutils vulnerabilities","summary":"Several security issues were fixed in GNU binutils.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-07-21T13:08:04.326367","description":"USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides\nthe corresponding update for Ubuntu 16.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that GNU binutils contained a large number of security\n issues. If a user or automated system were tricked into processing a\n specially-crafted file, a remote attacker could cause GNU binutils to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","description":"GNU assembler, linker and binary utilities","is_source":true},{"name":"binutils","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-aarch64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-alpha-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabi","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-arm-linux-gnueabihf","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-doc","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-hppa64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-m68k-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mips64el-linux-gnuabi64","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-mipsel-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-multiarch-dev","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc-linux-gnuspe","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-powerpc64le-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-s390x-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sh4-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-source","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"},{"name":"binutils-sparc64-linux-gnu","version":"2.26.1-1ubuntu1~16.04.8+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/binutils","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-19932","CVE-2019-9074","CVE-2018-18309","CVE-2017-12451","CVE-2017-16828","CVE-2017-7302","CVE-2017-9751","CVE-2017-17080","CVE-2018-12700","CVE-2017-14130","CVE-2018-18483","CVE-2018-7568","CVE-2017-14128","CVE-2017-9749","CVE-2017-12458","CVE-2019-9070","CVE-2017-9755","CVE-2018-10534","CVE-2017-9746","CVE-2019-12972","CVE-2017-7300","CVE-2018-9138","CVE-2017-7299","CVE-2016-4488","CVE-2017-15020","CVE-2017-9742","CVE-2017-17125","CVE-2017-14939","CVE-2019-14250","CVE-2017-14129","CVE-2017-12967","CVE-2017-17124","CVE-2018-12934","CVE-2017-7210","CVE-2017-8395","CVE-2017-7227","CVE-2017-12459","CVE-2017-9754","CVE-2018-20002","CVE-2016-4489","CVE-2019-9073","CVE-2018-8945","CVE-2017-12448","CVE-2016-4491","CVE-2018-17794","CVE-2017-13710","CVE-2017-14333","CVE-2017-15021","CVE-2017-14940","CVE-2017-14930","CVE-2017-7225","CVE-2017-7223","CVE-2017-12452","CVE-2017-6965","CVE-2018-18701","CVE-2017-15024","CVE-2018-10372","CVE-2018-18484","CVE-2017-16832","CVE-2017-9748","CVE-2017-15225","CVE-2018-7569","CVE-2017-16831","CVE-2018-17358","CVE-2018-6543","CVE-2017-7224","CVE-2016-4493","CVE-2017-17121","CVE-2017-9041","CVE-2019-9071","CVE-2018-19931","CVE-2017-9756","CVE-2018-18700","CVE-2018-10373","CVE-2019-17451","CVE-2018-12697","CVE-2018-18606","CVE-2018-12641","CVE-2017-17123","CVE-2016-4492","CVE-2017-16826","CVE-2017-9753","CVE-2018-6323","CVE-2017-8394","CVE-2017-16827","CVE-2017-12450","CVE-2016-6131","CVE-2017-14529","CVE-2017-9038","CVE-2016-2226","CVE-2017-9747","CVE-2016-4490","CVE-2017-12456","CVE-2018-20671","CVE-2018-10535","CVE-2016-4487","CVE-2017-15939","CVE-2018-7643","CVE-2018-13033","CVE-2017-9039","CVE-2017-15022","CVE-2017-8393","CVE-2018-20623","CVE-2017-9744","CVE-2018-7642","CVE-2017-9752","CVE-2018-12698","CVE-2018-12699","CVE-2017-15996","CVE-2017-9044","CVE-2018-6759","CVE-2017-9745","CVE-2018-7208","CVE-2017-6969","CVE-2017-12449","CVE-2017-14932","CVE-2017-7614","CVE-2017-12454","CVE-2018-1000876","CVE-2017-8396","CVE-2017-8397","CVE-2017-12455","CVE-2017-9954","CVE-2018-17360","CVE-2019-14444","CVE-2019-9075","CVE-2018-17985","CVE-2017-8398","CVE-2018-18607","CVE-2017-8421","CVE-2019-17450","CVE-2017-12799","CVE-2017-15938","CVE-2017-7301","CVE-2017-9750","CVE-2017-7226","CVE-2017-15025","CVE-2018-18605","CVE-2017-9042","CVE-2017-12457","CVE-2017-12453","CVE-2018-17359","CVE-2017-9040","CVE-2017-7209","CVE-2019-9077","CVE-2017-6966","CVE-2017-14938"]}]}],"offset":55980,"limit":20,"total_results":79316}