{"cves":[{"id":"CVE-2015-9096","published":"2017-06-12T00:00:00","updated_at":"2025-08-25T21:50:20.995623+00:00","description":"\nNet::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via\nCRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF\nsequences immediately before and after a DATA substring.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.mbsd.jp/Whitepaper/smtpi.pdf","https://hackerone.com/reports/137631","https://ubuntu.com/security/notices/USN-3365-1","https://www.cve.org/CVERecord?id=CVE-2015-9096"],"bugs":["https://github.com/rubysec/ruby-advisory-db/issues/215","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864860"],"patches":{"ruby1.9.1":[],"ruby2.0":[],"ruby2.3":["upstream: https://github.com/ruby/ruby/commit/0827a7e52ba3d957a634b063bf5a391239b9ffee"]},"tags":{},"packages":[{"name":"ruby1.9.1","source":"https://ubuntu.com/security/cve?package=ruby1.9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby1.9.1","debian":"https://tracker.debian.org/pkg/ruby1.9.1","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.9.3.484-2ubuntu1.3","component":null,"pocket":"security"}]},{"name":"ruby2.0","source":"https://ubuntu.com/security/cve?package=ruby2.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby2.0","debian":"https://tracker.debian.org/pkg/ruby2.0","statuses":[{"release_codename":"trusty","status":"released","description":"2.0.0.484-1ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.1-2~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.3.3-1ubuntu0.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3365-1"],"notices":[{"id":"USN-3365-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-25T17:52:34.131041","description":"It was discovered that Ruby DL::dlopen incorrectly handled opening\nlibraries. An attacker could possibly use this issue to open libraries with\ntainted names. This issue only applied to Ubuntu 14.04 LTS. (CVE-2009-5147)\n\nTony Arcieri, Jeffrey Walton, and Steffan Ullrich discovered that the Ruby\nOpenSSL extension incorrectly handled hostname wildcard matching. This\nissue only applied to Ubuntu 14.04 LTS. (CVE-2015-1855)\n\nChristian Hofstaedtler discovered that Ruby Fiddle::Handle incorrectly\nhandled certain crafted strings. An attacker could use this issue to cause\na denial of service, or possibly execute arbitrary code. This issue only\napplied to Ubuntu 14.04 LTS. (CVE-2015-7551)\n\nIt was discovered that Ruby Net::SMTP incorrectly handled CRLF sequences. A\nremote attacker could possibly use this issue to inject SMTP commands.\n(CVE-2015-9096)\n\nMarcin Noga discovered that Ruby incorrectly handled certain arguments in\na TclTkIp class method. An attacker could possibly use this issue to\nexecute arbitrary code. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2016-2337)\n\nIt was discovered that Ruby Fiddle::Function.new incorrectly handled\ncertain arguments. An attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-2339)\n\nIt was discovered that Ruby incorrectly handled the initialization vector\n(IV) in GCM mode. An attacker could possibly use this issue to bypass\nencryption. (CVE-2016-7798)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"ruby1.9.1","version":"1.9.3.484-2ubuntu1.3","description":"Object-oriented scripting language","is_source":true},{"name":"ruby2.0","version":"2.0.0.484-1ubuntu2.4","description":"Object-oriented scripting language","is_source":true},{"name":"libruby1.9.1","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"libruby2.0","version":"2.0.0.484-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.0","version_link":"https://launchpad.net/ubuntu/+source/ruby2.0/2.0.0.484-1ubuntu2.4","pocket":"security"},{"name":"libtcltk-ruby1.9.1","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ri1.9.1","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ruby1.9.1","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ruby1.9.1-dev","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ruby1.9.1-examples","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ruby1.9.1-full","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ruby1.9.3","version":"1.9.3.484-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1","version_link":"https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.484-2ubuntu1.3","pocket":"security"},{"name":"ruby2.0","version":"2.0.0.484-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.0","version_link":"https://launchpad.net/ubuntu/+source/ruby2.0/2.0.0.484-1ubuntu2.4","pocket":"security"},{"name":"ruby2.0-dev","version":"2.0.0.484-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.0","version_link":"https://launchpad.net/ubuntu/+source/ruby2.0/2.0.0.484-1ubuntu2.4","pocket":"security"},{"name":"ruby2.0-doc","version":"2.0.0.484-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.0","version_link":"https://launchpad.net/ubuntu/+source/ruby2.0/2.0.0.484-1ubuntu2.4","pocket":"security"},{"name":"ruby2.0-tcltk","version":"2.0.0.484-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.0","version_link":"https://launchpad.net/ubuntu/+source/ruby2.0/2.0.0.484-1ubuntu2.4","pocket":"security"}],"xenial":[{"name":"ruby2.3","version":"2.3.1-2~16.04.2","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.1-2~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~16.04.2","pocket":"security"},{"name":"ruby2.3","version":"2.3.1-2~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~16.04.2","pocket":"security"},{"name":"ruby2.3-dev","version":"2.3.1-2~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~16.04.2","pocket":"security"},{"name":"ruby2.3-doc","version":"2.3.1-2~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~16.04.2","pocket":"security"},{"name":"ruby2.3-tcltk","version":"2.3.1-2~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~16.04.2","pocket":"security"}],"zesty":[{"name":"ruby2.3","version":"2.3.3-1ubuntu0.1","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.3-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.3-1ubuntu0.1"},{"name":"ruby2.3","version":"2.3.3-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":"https://launchpad.net/ubuntu/+source/ruby2.3/2.3.3-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2009-5147","CVE-2015-1855","CVE-2015-7551","CVE-2015-9096","CVE-2016-2337","CVE-2016-2339","CVE-2016-7798"]}]},{"id":"CVE-2017-9527","published":"2017-06-11T17:29:00","updated_at":"2025-08-25T22:41:49.325066+00:00","description":"\nThe mark_context_stack function in gc.c in mruby through 1.2.0 allows\nattackers to cause a denial of service (heap-based use-after-free and\napplication crash) or possibly have unspecified other impact via a crafted\n.rb file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2017-9527"],"bugs":["https://github.com/mruby/mruby/issues/3486"],"patches":{"mruby":["upstream: https://github.com/mruby/mruby/commit/5c114c91d4ff31859fcd84cf8bf349b737b90d99"]},"tags":{},"packages":[{"name":"mruby","source":"https://ubuntu.com/security/cve?package=mruby","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mruby","debian":"https://tracker.debian.org/pkg/mruby","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.4.0-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.4.0-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.4.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0+20170601+git5e0e690-1, 1.3.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9526","published":"2017-06-10T00:00:00","updated_at":"2025-08-25T22:41:49.325066+00:00","description":"\nIn Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key\n(from side-channel observation during the signing process) can easily\nrecover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change\nto store this session key in secure memory, to ensure that constant-time\npoint operations are used in the MPI library.","ubuntu_description":"","notes":[{"author":"tyhicks","note":"EdDSA support was added in 1.6.0"}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3347-1","https://www.cve.org/CVERecord?id=CVE-2017-9526"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1042326"],"patches":{"libgcrypt20":["upstream: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=f9494b3f258e01b6af8bd3941ce436bcc00afc56","upstream: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=91456759b887e153c4d4ce19538d478df260cab2"],"libgcrypt11":[]},"tags":{},"packages":[{"name":"libgcrypt11","source":"https://ubuntu.com/security/cve?package=libgcrypt11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libgcrypt11","debian":"https://tracker.debian.org/pkg/libgcrypt11","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.5.3-2ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libgcrypt20","source":"https://ubuntu.com/security/cve?package=libgcrypt20","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libgcrypt20","debian":"https://tracker.debian.org/pkg/libgcrypt20","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.7.6-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.7.6-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.7.6-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.7.6-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.7.6-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.5-2ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.7.2-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.7.6-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3347-1"],"notices":[{"id":"USN-3347-1","title":"Libgcrypt vulnerabilities","summary":"Several security issues were fixed in Libgcrypt.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-03T18:40:30.402832","description":"Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot\nBruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal, and\nYuval Yarom discovered that Libgcrypt was susceptible to an attack via\nside channels. A local attacker could use this attack to recover RSA\nprivate keys. (CVE-2017-7526)\n\nIt was discovered that Libgcrypt was susceptible to an attack via\nside channels. A local attacker could use this attack to possibly recover\nEdDSA private keys. This issue only applied to Ubuntu 16.04 LTS, Ubuntu\n16.10 and Ubuntu 17.04. (CVE-2017-9526)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libgcrypt11","version":"1.5.3-2ubuntu4.5","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt11","version":"1.5.3-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt11","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.3-2ubuntu4.5","pocket":"security"},{"name":"libgcrypt11-dev","version":"1.5.3-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt11","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.3-2ubuntu4.5","pocket":"security"},{"name":"libgcrypt11-doc","version":"1.5.3-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt11","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.3-2ubuntu4.5","pocket":"security"},{"name":"libgcrypt11-udeb","version":"1.5.3-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt11","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.3-2ubuntu4.5","pocket":"security"}],"xenial":[{"name":"libgcrypt20","version":"1.6.5-2ubuntu0.3","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt11-dev","version":"1.5.4-3+really1.6.5-2ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.6.5-2ubuntu0.3","pocket":"security"},{"name":"libgcrypt20","version":"1.6.5-2ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.6.5-2ubuntu0.3","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.6.5-2ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.6.5-2ubuntu0.3","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.6.5-2ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.6.5-2ubuntu0.3","pocket":"security"},{"name":"libgcrypt20-udeb","version":"1.6.5-2ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.6.5-2ubuntu0.3","pocket":"security"}],"yakkety":[{"name":"libgcrypt20","version":"1.7.2-2ubuntu1.1","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt20","version":"1.7.2-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.7.2-2ubuntu1.1"}],"zesty":[{"name":"libgcrypt20","version":"1.7.6-1ubuntu0.1","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt20","version":"1.7.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.7.6-1ubuntu0.1"}]},"type":"USN","cves_ids":["CVE-2017-7526","CVE-2017-9526"]}]},{"id":"CVE-2017-0376","published":"2017-06-09T17:29:00","updated_at":"2025-08-25T22:15:51.238576+00:00","description":"\nThe hidden-service feature in Tor before 0.3.0.8 allows a denial of service\n(assertion failure and daemon exit) in the\nconnection_edge_process_relay_cell function via a BEGIN_DIR cell on a\nrendezvous circuit.","ubuntu_description":"\nIt was discovered that an assertion failure could cause Tor to exit\nresulting in a denial of service.","notes":[{"author":"sbeattie","note":"introduced in 0.2.2.1-alpha"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://trac.torproject.org/22494","https://www.cve.org/CVERecord?id=CVE-2017-0376"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864424"],"patches":{"tor":[]},"tags":{},"packages":[{"name":"tor","source":"https://ubuntu.com/security/cve?package=tor","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tor","debian":"https://tracker.debian.org/pkg/tor","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.3.0.8-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.3.0.8-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.2.4.27-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.0.8, 0.2.9.11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.2.9.11-1~deb9u1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-0375","published":"2017-06-09T17:29:00","updated_at":"2025-08-25T22:15:45.671988+00:00","description":"\nThe hidden-service feature in Tor before 0.3.0.8 allows a denial of service\n(assertion failure and daemon exit) in the relay_send_end_cell_from_edge_\nfunction via a malformed BEGIN cell.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"introduced in 0.3.0.1-alpha"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://trac.torproject.org/22493","https://blog.torproject.org/blog/tor-0308-released-fix-hidden-services-also-are-02429-02514-02612-0278-02814-and-02911","https://www.cve.org/CVERecord?id=CVE-2017-0375"],"bugs":[""],"patches":{"tor":[]},"tags":{},"packages":[{"name":"tor","source":"https://ubuntu.com/security/cve?package=tor","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tor","debian":"https://tracker.debian.org/pkg/tor","statuses":[{"release_codename":"trusty","status":"not-affected","description":"introduced in 0.3.0.1-alpha","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.0.8","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"introduced in 0.3.0.1-alpha","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"introduced in 0.3.0.1-alpha","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"introduced in 0.3.0.1-alpha","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9525","published":"2017-06-09T16:29:00","updated_at":"2025-08-18T17:07:17.371159+00:00","description":"\nIn the cron package through 3.0pl1-128 on Debian, and through\n3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for\ngroup-crontab-to-root privilege escalation via symlink attacks against\nunsafe usage of the chown and chmod programs.","ubuntu_description":"","notes":[{"author":"jj","note":"This appears to be mitigated by kernel symlink restrictions. The\ncrontabs dir has the sticky bit set\ndrwx-wx--T root crontab crontabs\nwhich means symlinks within the dir must have the same uid as the\ntarget.\nIt is still possible that a cron package update could trigger this race."},{"author":"seth-arnold","note":"I believe that actually _exploiting_ the bug requires\nupdating the cron package. So long as there's no updates for cron,\nthe vulnerable code doesn't run. So if we find a second bug in\ncron then we really should fix the race condition at the same\ntime, but so long as we don't push a cron update, the vulnerable\ncode just plain doesn't run.\nthe patch just narrows the time window for the race condition."}],"codename":null,"priority":"low","cvss3":6.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/06/08/3","http://bugs.debian.org/864466","https://ubuntu.com/security/notices/USN-5259-1","https://ubuntu.com/security/notices/USN-5259-2","https://ubuntu.com/security/notices/USN-5259-3","https://www.cve.org/CVERecord?id=CVE-2017-9525"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864466","https://bugs.launchpad.net/ubuntu/+source/cron/+bug/1971895 (regression)","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892720 (regression)"],"patches":{"cron":["upstream: https://salsa.debian.org/debian/cron/-/commit/a10ab4e346e941aaa92f4b671a96895392b917af","upstream: https://salsa.debian.org/debian/cron/-/commit/230478512cc82d879d727f6dfc18040bdd48c9d9"]},"tags":{},"packages":[{"name":"cron","source":"https://ubuntu.com/security/cve?package=cron","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=cron","debian":"https://tracker.debian.org/pkg/cron","statuses":[{"release_codename":"bionic","status":"released","description":"3.0pl1-128.1ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.0pl1-128ubuntu2+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0pl1-129","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.0pl1-134ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5259-1","USN-5259-2","USN-5259-3"],"notices":[{"id":"USN-5259-1","title":"Cron vulnerabilities","summary":"Several security issues were fixed in Cron.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-02-01T14:38:29.524042","description":"It was discovered that the postinst maintainer script in Cron unsafely\nhandled file permissions during package install or update operations.\nAn attacker could possibly use this issue to perform a privilege\nescalation attack. (CVE-2017-9525)\n\nFlorian Weimer discovered that Cron incorrectly handled certain memory\noperations during crontab file creation. An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2019-9704)\n\nIt was discovered that Cron incorrectly handled user input during crontab\nfile creation. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2019-9705)\n\nIt was discovered that Cron contained a use-after-free vulnerability in\nits force_rescan_user function. An attacker could possibly use this issue\nto cause a denial of service. (CVE-2019-9706)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"cron","version":"3.0pl1-128ubuntu2+esm1","description":"process scheduling daemon","is_source":true},{"name":"cron","version":"3.0pl1-128ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cron","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2019-9704","CVE-2019-9705","CVE-2019-9706","CVE-2017-9525"]},{"id":"USN-5259-2","title":"Cron vulnerabilities","summary":"Several security issues were fixed in Cron.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-05-06T08:42:24.468406","description":"USN-5259-1 fixed several vulnerabilities in Cron. This update provides\nthe corresponding update for Ubuntu 18.04 LTS. \n\nOriginal advisory details:\n\n It was discovered that the postinst maintainer script in Cron unsafely\n handled file permissions during package install or update operations.\n An attacker could possibly use this issue to perform a privilege\n escalation attack. (CVE-2017-9525)\n \n Florian Weimer discovered that Cron incorrectly handled certain memory\n operations during crontab file creation. An attacker could possibly use\n this issue to cause a denial of service. (CVE-2019-9704)\n \n It was discovered that Cron incorrectly handled user input during crontab\n file creation. An attacker could possibly use this issue to cause a denial\n of service. (CVE-2019-9705)\n \n It was discovered that Cron contained a use-after-free vulnerability in\n its force_rescan_user function. An attacker could possibly use this issue\n to cause a denial of service. (CVE-2019-9706)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"cron","version":"3.0pl1-128.1ubuntu1.1","description":"process scheduling daemon","is_source":true},{"name":"cron","version":"3.0pl1-128.1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cron","version_link":"https://launchpad.net/ubuntu/+source/cron/3.0pl1-128.1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-9706","CVE-2019-9705","CVE-2017-9525","CVE-2019-9704"]},{"id":"USN-5259-3","title":"Cron regression","summary":"USN-5259-1 and USN-5259-2 introduced a regression in Cron.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":["https://ubuntu.com/security/notices/USN-5259-2","https://launchpad.net/bugs/1971895"],"published":"2022-05-11T00:25:41.666008","description":"USN-5259-1 and USN-5259-2 fixed vulnerabilities in Cron. Unfortunately\nthat update was incomplete and could introduce a regression. This update\nfixes the problem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n It was discovered that the postinst maintainer script in Cron unsafely\n handled file permissions during package install or update operations.\n An attacker could possibly use this issue to perform a privilege\n escalation attack. (CVE-2017-9525)\n \n Florian Weimer discovered that Cron incorrectly handled certain memory\n operations during crontab file creation. An attacker could possibly use\n this issue to cause a denial of service. (CVE-2019-9704)\n \n It was discovered that Cron incorrectly handled user input during crontab\n file creation. An attacker could possibly use this issue to cause a denial\n of service. (CVE-2019-9705)\n \n It was discovered that Cron contained a use-after-free vulnerability in\n its force_rescan_user function. An attacker could possibly use this issue\n to cause a denial of service. (CVE-2019-9706)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"cron","version":"3.0pl1-128.1ubuntu1.2","description":"process scheduling daemon","is_source":true},{"name":"cron","version":"3.0pl1-128.1ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cron","version_link":"https://launchpad.net/ubuntu/+source/cron/3.0pl1-128.1ubuntu1.2","pocket":"security"}],"xenial":[{"name":"cron","version":"3.0pl1-128ubuntu2+esm2","description":"process scheduling daemon","is_source":true},{"name":"cron","version":"3.0pl1-128ubuntu2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cron","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2017-9525"]}]},{"id":"CVE-2016-7837","published":"2017-06-09T16:29:00","updated_at":"2025-08-25T22:11:10.034753+00:00","description":"\nBuffer overflow in BlueZ 5.41 and earlier allows an attacker to execute\narbitrary code via the parse_line function used in some userland utilities.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4311-1","https://www.cve.org/CVERecord?id=CVE-2016-7837"],"bugs":[""],"patches":{"bluez":["upstream: http://git.kernel.org/cgit/bluetooth/bluez.git/commit/?id=8514068150759c1d6a46d4605d2351babfde1601"]},"tags":{},"packages":[{"name":"bluez","source":"https://ubuntu.com/security/cve?package=bluez","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=bluez","debian":"https://tracker.debian.org/pkg/bluez","statuses":[{"release_codename":"trusty","status":"released","description":"4.101-0ubuntu13.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"5.43-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"5.43-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.43-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"5.43-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"5.43-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"5.43-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.43-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.37-0ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-4311-1"],"notices":[{"id":"USN-4311-1","title":"BlueZ vulnerabilities","summary":"Several security issues were fixed in BlueZ.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-03-30T17:49:16.267749","description":"It was discovered that BlueZ incorrectly handled bonding HID and HOGP\ndevices. A local attacker could possibly use this issue to impersonate\nnon-bonded devices. (CVE-2020-0556)\n\nIt was discovered that BlueZ incorrectly handled certain commands. A local\nattacker could use this issue to cause BlueZ to crash, resulting in a\ndenial of service, or possibly execute arbitrary code. This issue only\naffected Ubuntu 16.04 LTS. (CVE-2016-7837)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"bluez","version":"5.48-0ubuntu3.4","description":"Bluetooth tools and daemons","is_source":true},{"name":"bluetooth","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"bluez","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"bluez-cups","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"bluez-hcidump","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"bluez-obexd","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"bluez-tests","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"libbluetooth-dev","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"},{"name":"libbluetooth3","version":"5.48-0ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.48-0ubuntu3.4","pocket":"security"}],"eoan":[{"name":"bluez","version":"5.50-0ubuntu5.1","description":"Bluetooth tools and daemons","is_source":true},{"name":"bluetooth","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"bluez","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"bluez-cups","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"bluez-hcidump","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"bluez-obexd","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"bluez-tests","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"libbluetooth-dev","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"},{"name":"libbluetooth3","version":"5.50-0ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.50-0ubuntu5.1"}],"xenial":[{"name":"bluez","version":"5.37-0ubuntu5.3","description":"Bluetooth tools and daemons","is_source":true},{"name":"bluetooth","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"bluez","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"bluez-cups","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"bluez-hcidump","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"bluez-obexd","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"bluez-tests","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"libbluetooth-dev","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"},{"name":"libbluetooth3","version":"5.37-0ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/bluez","version_link":"https://launchpad.net/ubuntu/+source/bluez/5.37-0ubuntu5.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-7837","CVE-2020-0556"]}]},{"id":"CVE-2017-7507","published":"2017-06-09T00:00:00","updated_at":"2025-08-25T22:37:48.884672+00:00","description":"\nGnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer\ndereference while decoding a status response TLS extension with valid\ncontents. This could lead to a crash of the GnuTLS server application.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gnutls.org/security.html#GNUTLS-SA-2017-4","https://ubuntu.com/security/notices/USN-3318-1","https://www.cve.org/CVERecord?id=CVE-2017-7507"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864560"],"patches":{"gnutls26":[],"gnutls28":["upstream: https://gitlab.com/gnutls/gnutls/commit/4c4d35264fada08b6536425c051fb8e0b05ee86b","upstream: https://gitlab.com/gnutls/gnutls/commit/3efb6c5fd0e3822ec11879d5bcbea0e8d322cd03","upstream: https://gitlab.com/gnutls/gnutls/commit/e1d6c59a7b0392fb3b8b75035614084a53e2c8c9","upstream: https://gitlab.com/gnutls/gnutls/commit/9d95c912b5843e664c8210887a6719f02a9028be","upstream: https://gitlab.com/gnutls/gnutls/commit/023a20d21b762918d3e1ab25a207ecf874ba21a9","upstream: https://gitlab.com/gnutls/gnutls/commit/3ade67eb6859a5a074f981480e5663ea92a59380"]},"tags":{},"packages":[{"name":"gnutls26","source":"https://ubuntu.com/security/cve?package=gnutls26","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnutls26","debian":"https://tracker.debian.org/pkg/gnutls26","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"gnutls28","source":"https://ubuntu.com/security/cve?package=gnutls28","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gnutls28","debian":"https://tracker.debian.org/pkg/gnutls28","statuses":[{"release_codename":"artful","status":"released","description":"3.5.8-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.5.8-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"3.5.8-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"3.5.8-6ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.5.13,3.5.8-6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.4.10-4ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"3.5.3-5ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"3.5.6-4ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":["USN-3318-1"],"notices":[{"id":"USN-3318-1","title":"GnuTLS vulnerabilities","summary":"Several security issues were fixed in GnuTLS.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-06-13T17:01:32.544509","description":"Hubert Kario discovered that GnuTLS incorrectly handled decoding a status\nresponse TLS extension. A remote attacker could possibly use this issue to\ncause GnuTLS to crash, resulting in a denial of service. This issue only\napplied to Ubuntu 16.04 LTS, Ubuntu 16.10 and Ubuntu 17.04. (CVE-2017-7507)\n\nIt was discovered that GnuTLS incorrectly handled decoding certain OpenPGP\ncertificates. A remote attacker could use this issue to cause GnuTLS to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2017-7869)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"gnutls26","version":"2.12.23-12ubuntu2.8","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.0.11+really2.12.23-12ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.8","pocket":"security"},{"name":"gnutls26-doc","version":"2.12.23-12ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.8","pocket":"security"},{"name":"libgnutls-dev","version":"2.12.23-12ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.8","pocket":"security"},{"name":"libgnutls-openssl27","version":"2.12.23-12ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.8","pocket":"security"},{"name":"libgnutls26","version":"2.12.23-12ubuntu2.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.8","pocket":"security"},{"name":"libgnutlsxx27","version":"2.12.23-12ubuntu2.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls26","version_link":"https://launchpad.net/ubuntu/+source/gnutls26/2.12.23-12ubuntu2.8","pocket":"security"}],"xenial":[{"name":"gnutls28","version":"3.4.10-4ubuntu1.3","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"gnutls-doc","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"guile-gnutls","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"libgnutls-dev","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"libgnutls-openssl27","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"libgnutls28-dev","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"libgnutls30","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"},{"name":"libgnutlsxx28","version":"3.4.10-4ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.4.10-4ubuntu1.3","pocket":"security"}],"yakkety":[{"name":"gnutls28","version":"3.5.3-5ubuntu1.2","description":"GNU TLS library","is_source":true},{"name":"libgnutls30","version":"3.5.3-5ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.5.3-5ubuntu1.2"}],"zesty":[{"name":"gnutls28","version":"3.5.6-4ubuntu4.1","description":"GNU TLS library","is_source":true},{"name":"libgnutls30","version":"3.5.6-4ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.5.6-4ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2017-7507","CVE-2017-7869"]}]},{"id":"CVE-2015-1786","published":"2017-06-08T21:29:00","updated_at":"2025-08-25T21:35:15.429872+00:00","description":"\nCross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in\nZend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"this issue was introduced in 2.3."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://framework.zend.com/security/advisory/ZF2015-03","https://www.cve.org/CVERecord?id=CVE-2015-1786"],"bugs":[""],"patches":{"zendframework":[]},"tags":{},"packages":[{"name":"zendframework","source":"https://ubuntu.com/security/cve?package=zendframework","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=zendframework","debian":"https://tracker.debian.org/pkg/zendframework","statuses":[{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.3.6","component":null,"pocket":"security"},{"release_codename":"utopic","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-1379","published":"2017-06-08T21:29:00","updated_at":"2025-08-25T21:34:51.644913+00:00","description":"\nThe signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8\nallow remote attackers to cause a denial of service (process freeze or\ncrash).","ubuntu_description":"\nIt was discovered that socat incorrectly handled signals. A remote attacker\ncould possibly use this issue to cause a denial of service.","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2015-1379"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776234"],"patches":{"socat":[]},"tags":{},"packages":[{"name":"socat","source":"https://ubuntu.com/security/cve?package=socat","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=socat","debian":"https://tracker.debian.org/pkg/socat","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.7.3.2-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.7.2.3-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.7.3.0","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.7.3.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.7.3.2-2ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4473","published":"2017-06-08T20:29:00","updated_at":"2025-08-25T22:03:30.177656+00:00","description":"\n/ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to\nexecute arbitrary code.  NOTE: Introduced as part of an incomplete fix to\nCVE-2015-6833.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in fix for CVE-2015-6833 on 5.6 only\nby this commit:\nhttps://git.php.net/?p=php-src.git;a=commitdiff;h=eb7ba73079b73ca4ef91307ae1ef30b43468717b\n5.5 is not affected"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://php.net/ChangeLog-5.php#5.6.23","https://www.cve.org/CVERecord?id=CVE-2016-4473"],"bugs":["https://bugs.php.net/bug.php?id=72321"],"patches":{"php5":["upstream: http://git.php.net/?p=php-src.git;a=commitdiff;h=d144590d38fa321b46b8e199c754006318985c84"],"php7.0":[]},"tags":{},"packages":[{"name":"php5","source":"https://ubuntu.com/security/cve?package=php5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php5","debian":"https://tracker.debian.org/pkg/php5","statuses":[{"release_codename":"precise","status":"not-affected","description":"5.3.10-1ubuntu3.24","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"5.5.9+dfsg-1ubuntu4.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.23","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"php7.0","source":"https://ubuntu.com/security/cve?package=php7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=php7.0","debian":"https://tracker.debian.org/pkg/php7.0","statuses":[{"release_codename":"xenial","status":"not-affected","description":"7.0.8-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-7050","published":"2017-06-08T19:29:00","updated_at":"2025-09-15T14:49:43.648244+00:00","description":"\nSerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red\nHat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red\nHat Enterprise Linux Workstation 7 allows remote attackers to execute\narbitrary code.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"The SerializableProvider has been disabled by default in 3.0.17"},{"author":"noam-ns","note":"No fix is available beyond disabling the feature, it was\neventually deprecated and abandonned upstream"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-7050","https://ubuntu.com/security/notices/USN-7630-1"],"bugs":[""],"patches":{"resteasy":["upstream: https://github.com/resteasy/Resteasy/commit/bb8657c9808763d4c4b9227f6a2fcf47b9146636"],"resteasy3.0":[]},"tags":{},"packages":[{"name":"resteasy","source":"https://ubuntu.com/security/cve?package=resteasy","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=resteasy","debian":"https://tracker.debian.org/pkg/resteasy","statuses":[{"release_codename":"impish","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.0.6-3ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.18-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.0.17","component":null,"pocket":"security"}]},{"name":"resteasy3.0","source":"https://ubuntu.com/security/cve?package=resteasy3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=resteasy3.0","debian":"https://tracker.debian.org/pkg/resteasy3.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0.18","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0.18","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0.18","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.0.18","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.0.18","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.18","component":null,"pocket":"security"}]}],"notices_ids":["USN-7630-1"],"notices":[{"id":"USN-7630-1","title":"RESTEasy vulnerabilities","summary":"Several security issues were fixed in resteasy, resteasy3.0.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-10T14:30:24.941578","description":"It was discovered that RESTEasy made insufficient use of random values in\nasynchronous jobs. An attacker could possibly use this issue to steal\nuser data. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-6345)\n\nIt was discovered that RESTEasy enabled a vulnerable GZIP decompression\nmodule by default. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2016-6346)\n\nIt was discovered that RESTEasy improperly made use of unsanitized data\nwhile handling certain errors. An attacker could possibly use this issue\nto cause a denial of service or execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2016-6347)\n\nIt was discovered that RESTEasy enabled a vulnerable JSON manipulation\nmodule by default. An attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2016-6348)\n\nIt was discovered that RESTEasy enabled a vulnerable deserialization\nmodule by default. An attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2016-7050)\n\nNikos Papadopoulos discovered that RESTEasy improperly handled URL encoding\nwhen certain errors occur. An attacker could possibly use this issue to\nmodify the app's behavior for other users throughout the network.\nThis issue did not affect resteasy3.0 in Ubuntu 24.04 LTS, Ubuntu 24.10,\nand Ubuntu 25.04. (CVE-2020-10688)\n\nMirko Selber discovered that RESTEasy improperly validated user input\nduring HTTP response construction. An attacker could possibly use this\nissue to to cause a denial of service or execute arbitrary code.\nThis issue did not affect resteasy3.0 in Ubuntu 22.04 LTS,\nUbuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2020-1695)\n\nIt was discovered that RESTEasy improperly handled receiving the\nWebApplicationException during a client call. An attacker could possibly\nuse this issue to obtain potentially sensitive server information.\n(CVE-2020-25633)\n\nIt was discovered that RESTEasy improperly populated exception responses\nwith endpoint class and method names. An attacker could possibly use this\nissue to obtain potentially sensitive server information. (CVE-2021-20289)\n\nIt was discovered that RESTEasy used improper permissions when creating\ntemporary files. An attacker could possibly use this issue to get access to\nsensitive data. (CVE-2023-0482)\n\nIt was discovered that RESTEasy improperly handled certain HTTP requests\ncontaining ASCII control characters. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2024-9622)","is_hidden":false,"release_packages":{"bionic":[{"name":"resteasy","version":"3.0.26-1~18.04.1~esm1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"resteasy3.0","version":"3.0.26-1~18.04.1~esm1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy3.0-java","version":"3.0.26-1~18.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy3.0","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"resteasy","version":"3.0.26-1ubuntu0.1~esm1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"resteasy3.0","version":"3.0.26-1ubuntu0.1~esm1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy3.0-java","version":"3.0.26-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy3.0","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"resteasy","version":"3.0.26-3ubuntu0.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"resteasy3.0","version":"3.0.26-3ubuntu0.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy3.0-java","version":"3.0.26-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy3.0","version_link":"https://launchpad.net/ubuntu/+source/resteasy3.0/3.0.26-3ubuntu0.1","pocket":"security"}],"noble":[{"name":"resteasy","version":"3.0.26-6ubuntu0.24.04.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"resteasy3.0","version":"3.0.26-6ubuntu0.24.04.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy3.0-java","version":"3.0.26-6ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy3.0","version_link":"https://launchpad.net/ubuntu/+source/resteasy3.0/3.0.26-6ubuntu0.24.04.1","pocket":"security"}],"oracular":[{"name":"resteasy","version":"3.0.26-6ubuntu0.24.10.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"resteasy3.0","version":"3.0.26-6ubuntu0.24.10.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy3.0-java","version":"3.0.26-6ubuntu0.24.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy3.0","version_link":"https://launchpad.net/ubuntu/+source/resteasy3.0/3.0.26-6ubuntu0.24.10.1","pocket":"security"}],"plucky":[{"name":"resteasy","version":"3.6.2-3ubuntu0.25.04.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"resteasy3.0","version":"3.0.26-6ubuntu0.25.04.1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy-java","version":"3.6.2-3ubuntu0.25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy","version_link":"https://launchpad.net/ubuntu/+source/resteasy/3.6.2-3ubuntu0.25.04.1","pocket":"security"},{"name":"libresteasy3.0-java","version":"3.0.26-6ubuntu0.25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy3.0","version_link":"https://launchpad.net/ubuntu/+source/resteasy3.0/3.0.26-6ubuntu0.25.04.1","pocket":"security"}],"xenial":[{"name":"resteasy","version":"3.0.6-3ubuntu0.1~esm1","description":"A project that provides various frameworks to help you build RESTful Web Services and RESTful Java applications","is_source":true},{"name":"libresteasy-java","version":"3.0.6-3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/resteasy","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-20289","CVE-2016-6348","CVE-2020-1695","CVE-2016-7050","CVE-2020-10688","CVE-2016-6347","CVE-2023-0482","CVE-2016-6345","CVE-2016-6346","CVE-2020-25633","CVE-2024-9622"]}]},{"id":"CVE-2016-5416","published":"2017-06-08T19:29:00","updated_at":"2025-07-11T08:08:59.538321+00:00","description":"\n389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red\nHat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server\n6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows\nremote attackers to read the default Access Control Instructions.","ubuntu_description":"","notes":[{"author":"hlibk","note":"Upstream has marked this vulnerability as \"Won't fix.\""},{"author":"leosilva","note":"has not patch available."}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://fedorahosted.org/389/ticket/48852","https://www.cve.org/CVERecord?id=CVE-2016-5416"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1349540","https://github.com/389ds/389-ds-base/issues/1912"],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was ignored [see notes]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [see notes]","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5405","published":"2017-06-08T19:29:00","updated_at":"2025-08-25T22:06:39.038227+00:00","description":"\n389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red\nHat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server\n6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows\nremote attackers to obtain user passwords.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"affects systems where passwords are stored in plain text or\nunsalted hashs using weak algorithms"},{"author":"leosilva","note":"code in trusty is quite different from patch."}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5405"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=842121","https://bugzilla.redhat.com/show_bug.cgi?id=1358865"],"patches":{"389-ds-base":["other: https://pagure.io/389-ds-base/c/762219a35005914c6c088d915ac9346ce7e28512"]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.3.5.15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.5.15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.5.15-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-4992","published":"2017-06-08T19:29:00","updated_at":"2025-08-26T11:55:13.683398+00:00","description":"\n389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red\nHat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server\n6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows\nremote attackers to infer the existence of RDN component objects.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-4992","https://www.cve.org/CVERecord?id=CVE-2016-4992"],"bugs":[""],"patches":{"389-ds-base":["other: https://pagure.io/389-ds-base/c/caa351ae0cc81cbf2309a43c5f74b359cda152d0"]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3099","published":"2017-06-08T19:29:00","updated_at":"2025-08-26T11:54:05.517589+00:00","description":"\nmod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC\nNode 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux\nWorkstation 7 allows remote attackers to force the use of ciphers that were\nnot intended to be enabled.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-3099"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=822461"],"patches":{"libapache2-mod-nss":[]},"tags":{},"packages":[{"name":"libapache2-mod-nss","source":"https://ubuntu.com/security/cve?package=libapache2-mod-nss","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libapache2-mod-nss","debian":"https://tracker.debian.org/pkg/libapache2-mod-nss","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.0.14-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.0.14-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2014-3498","published":"2017-06-08T18:29:00","updated_at":"2025-08-25T21:17:45.283408+00:00","description":"\nThe user module in ansible before 1.6.6 allows remote authenticated users\nto execute arbitrary commands.","ubuntu_description":"\nIt was discovered that Ansible improperly handled the output of certain commands.\nAn attacker could use this vulnerability to execute arbitrary commands on the\nansible manging host.","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/ansible/ansible/commit/8ed6350e65c82292a631f08845dfaacffe7f07f5 (v1.7.0)","https://www.cve.org/CVERecord?id=CVE-2014-3498"],"bugs":[""],"patches":{"ansible":[]},"tags":{},"packages":[{"name":"ansible","source":"https://ubuntu.com/security/cve?package=ansible","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ansible","debian":"https://tracker.debian.org/pkg/ansible","statuses":[{"release_codename":"artful","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.4+dfsg-1ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.7.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"1.9.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-8108","published":"2017-06-08T16:29:00","updated_at":"2025-08-26T12:01:36.252587+00:00","description":"\nUnspecified tests in Lynis before 2.5.0 allow local users to write to\narbitrary files or possibly gain privileges via a symlink attack on a\ntemporary file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"symlink hardening"}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://cisofy.com/security/cve/cve-2017-8108/","https://github.com/CISOfy/lynis/releases/tag/2.5.0","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJXMPYANXHI25NQZ36QMXNXANDRAA5YG/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJHLLWNW7NASVXCK24YBSIUQQPWGCMB5/","https://www.cve.org/CVERecord?id=CVE-2017-8108"],"bugs":[""],"patches":{"lynis":["upstream: https://github.com/CISOfy/lynis/commit/a9b67dc67579539436f49b7835d21abe870b1564"]},"tags":{},"packages":[{"name":"lynis","source":"https://ubuntu.com/security/cve?package=lynis","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lynis","debian":"https://tracker.debian.org/pkg/lynis","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.5.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5878","published":"2017-06-08T16:29:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nThe AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the\nclasses for which it performs deserialization, which allows remote\nattackers to execute arbitrary code via crafted serialized Java data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/05/22/2","https://www.github.com/mbechler/marshalsec/blob/master/marshalsec.pdf?raw=true","https://www.cve.org/CVERecord?id=CVE-2017-5878"],"bugs":[""],"patches":{"red5":[]},"tags":{},"packages":[{"name":"red5","source":"https://ubuntu.com/security/cve?package=red5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=red5","debian":"https://tracker.debian.org/pkg/red5","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.0.8","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9520","published":"2017-06-08T14:29:00","updated_at":"2025-08-26T12:02:23.808190+00:00","description":"\nThe r_config_set function in libr/config/config.c in radare2 1.5.0 allows\nremote attackers to cause a denial of service (use-after-free and\napplication crash) via a crafted DEX file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/radare/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005","https://github.com/radare/radare2/issues/7698","https://www.cve.org/CVERecord?id=CVE-2017-9520"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/radare2/+bug/1882889"],"patches":{"radare2":["upstream: https://github.com/radare/radare2/commit/f85bc674b2a2256a364fe796351bc1971e106005"]},"tags":{},"packages":[{"name":"radare2","source":"https://ubuntu.com/security/cve?package=radare2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=radare2","debian":"https://tracker.debian.org/pkg/radare2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.0+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.3.0+dfsg-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":56680,"limit":20,"total_results":79316}