{"cves":[{"id":"CVE-2016-9961","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T22:15:22.144835+00:00","description":"\ngame-music-emu before 0.6.1 mishandles unspecified integer values.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://scarybeastsecurity.blogspot.de/2016/12/redux-compromising-linux-using-snes.html","http://www.openwall.com/lists/oss-security/2016/12/15/1","https://www.cve.org/CVERecord?id=CVE-2016-9961"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848071"],"patches":{"game-music-emu":[]},"tags":{},"packages":[{"name":"game-music-emu","source":"https://ubuntu.com/security/cve?package=game-music-emu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=game-music-emu","debian":"https://tracker.debian.org/pkg/game-music-emu","statuses":[{"release_codename":"precise","status":"released","description":"0.5.5-2ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.5.5-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.0-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.6.0-3ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.6.0-3ubuntu0.16.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9960","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T22:15:22.144835+00:00","description":"\ngame-music-emu before 0.6.1 allows local users to cause a denial of service\n(divide by zero and process crash).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://scarybeastsecurity.blogspot.de/2016/12/redux-compromising-linux-using-snes.html","http://www.openwall.com/lists/oss-security/2016/12/15/1","https://www.cve.org/CVERecord?id=CVE-2016-9960"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848071"],"patches":{"game-music-emu":[]},"tags":{},"packages":[{"name":"game-music-emu","source":"https://ubuntu.com/security/cve?package=game-music-emu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=game-music-emu","debian":"https://tracker.debian.org/pkg/game-music-emu","statuses":[{"release_codename":"precise","status":"released","description":"0.5.5-2ubuntu0.12.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.5.5-2ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.0-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.6.0-3ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.6.0-3ubuntu0.16.10.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-3066","published":"2017-06-06T18:29:00","updated_at":"2025-07-11T07:38:16.353330+00:00","description":"\nThe spice-gtk widget allows remote authenticated users to obtain\ninformation from the host clipboard.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"Hans de Goede comments in the Red Hat bug that the clipboard\nsynchronization can be turned off at the server. I'm marking this 'low'\nas a result of the configuration option being available."}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1320263","https://www.cve.org/CVERecord?id=CVE-2016-3066"],"bugs":[""],"patches":{"spice-gtk":[]},"tags":{},"packages":[{"name":"spice-gtk","source":"https://ubuntu.com/security/cve?package=spice-gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=spice-gtk","debian":"https://tracker.debian.org/pkg/spice-gtk","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-2192","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T21:56:56.231360+00:00","description":"\nPostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter\ntype mappings for types they do not own.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://tada.github.io/pljava/releasenotes.html","https://www.cve.org/CVERecord?id=CVE-2016-2192"],"bugs":[""],"patches":{"postgresql-pljava":[]},"tags":{},"packages":[{"name":"postgresql-pljava","source":"https://ubuntu.com/security/cve?package=postgresql-pljava","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-pljava","debian":"https://tracker.debian.org/pkg/postgresql-pljava","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-0768","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T21:50:59.651924+00:00","description":"\nPostgreSQL PL/Java after 9.0 does not honor access controls on large\nobjects.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://tada.github.io/pljava/releasenotes.html","https://www.cve.org/CVERecord?id=CVE-2016-0768"],"bugs":[""],"patches":{"postgresql-pljava":[]},"tags":{},"packages":[{"name":"postgresql-pljava","source":"https://ubuntu.com/security/cve?package=postgresql-pljava","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-pljava","debian":"https://tracker.debian.org/pkg/postgresql-pljava","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-0767","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T21:50:59.651924+00:00","description":"\nPostgreSQL PL/Java before 1.5.0 allows remote authenticated users with\nUSAGE permission on the public schema to alter the public schema classpath.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://tada.github.io/pljava/releasenotes.html","https://www.cve.org/CVERecord?id=CVE-2016-0767"],"bugs":[""],"patches":{"postgresql-pljava":[]},"tags":{},"packages":[{"name":"postgresql-pljava","source":"https://ubuntu.com/security/cve?package=postgresql-pljava","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=postgresql-pljava","debian":"https://tracker.debian.org/pkg/postgresql-pljava","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needs-triage]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-0726","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T21:50:45.161407+00:00","description":"\nThe Fedora Nagios package uses \"nagiosadmin\" as the default password for\nthe \"nagiosadmin\" administrator account, which makes it easier for remote\nattackers to obtain access by leveraging knowledge of the credentials.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Ubuntu nagios3 package asks for password during installation"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-0726"],"bugs":[""],"patches":{"nagios3":[]},"tags":{},"packages":[{"name":"nagios3","source":"https://ubuntu.com/security/cve?package=nagios3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nagios3","debian":"https://tracker.debian.org/pkg/nagios3","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-1207","published":"2017-06-06T18:29:00","updated_at":"2025-08-25T21:33:47.181244+00:00","description":"\nDouble-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome\n41.0.2251.0 allows remote attackers to cause a denial of service (memory\ncorruption and crash) via a crafted .m4a file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reproducer in chromium bug report"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.chromium.org/p/chromium/issues/detail?id=444539","https://gist.github.com/bittorrent3389/8fee7cdaa73d1d351ee9","https://crrev.com/d6cc2ec3bf2acdcb364fda90374158641b4e73be","https://www.cve.org/CVERecord?id=CVE-2015-1207"],"bugs":["https://bugs.chromium.org/p/chromium/issues/detail?id=444539"],"patches":{"chromium-browser":[],"ffmpeg":["upstream: http://git.videolan.org/?p=ffmpeg.git;a=commitdiff;h=3859868c75313e318ebc5d0d33baada62d45dd75"],"oxide-qt":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"artful","status":"not-affected","description":"61.0.3163.100-0ubuntu1.1378","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"61.0.3163.100-0ubuntu1.1378","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"61.0.3163.100-0ubuntu1.1378","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"61.0.3163.100-0ubuntu0.16.04.1306","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"61.0.3163.100-0ubuntu0.17.04.1377","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [61.0.3163.100-0ubuntu0.14.04.1202]","component":null,"pocket":"security"}]},{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.6","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.6","component":null,"pocket":"security"}]},{"name":"oxide-qt","source":"https://ubuntu.com/security/cve?package=oxide-qt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=oxide-qt","debian":"https://tracker.debian.org/pkg/oxide-qt","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [Ubuntu touch end-of-life]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9469","published":"2017-06-06T00:00:00","updated_at":"2025-08-25T22:41:43.751119+00:00","description":"\nIn Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files,\nit tries to find the terminating quote one byte before the allocated\nmemory. Thus, remote attackers might be able to cause a crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://irssi.org/security/irssi_sa_2017_06.txt","http://openwall.com/lists/oss-security/2017/06/06/4","https://ubuntu.com/security/notices/USN-3317-1","https://www.cve.org/CVERecord?id=CVE-2017-9469"],"bugs":[""],"patches":{"irssi":["upstream: https://github.com/irssi/irssi/commit/30a92754bb650c3dedd507d41110443142899a65"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"trusty","status":"released","description":"0.8.15-5ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.8.19-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.8.20-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3317-1"],"notices":[{"id":"USN-3317-1","title":"Irssi vulnerabilities","summary":"Irssi could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"After a standard system update you need to restart Irssi to make all the\nnecessary changes.\n","references":[],"published":"2017-06-12T12:30:47.783054","description":"It was discovered that Irssi incorrectly handled certain DCC messages. A\nmalicious IRC server could use this issue to cause Irssi to crash,\nresulting in a denial of service. (CVE-2017-9468)\n\nJoseph Bisch discovered that Irssi incorrectly handled receiving\nincorrectly quoted DCC files. A remote attacker could possibly use this\nissue to cause Irssi to crash, resulting in a denial of service.\n(CVE-2017-9469)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.2","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.2","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.2","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.4","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.4","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.4","pocket":"security"}],"yakkety":[{"name":"irssi","version":"0.8.19-1ubuntu2.2","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu2.2"}],"zesty":[{"name":"irssi","version":"0.8.20-2ubuntu2.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.20-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.20-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2017-9468","CVE-2017-9469"]}]},{"id":"CVE-2017-9468","published":"2017-06-06T00:00:00","updated_at":"2025-08-25T22:41:43.751119+00:00","description":"\nIn Irssi before 1.0.3, when receiving a DCC message without source\nnick/host, it attempts to dereference a NULL pointer. Thus, remote IRC\nservers can cause a crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://irssi.org/security/irssi_sa_2017_06.txt","http://openwall.com/lists/oss-security/2017/06/06/4","https://ubuntu.com/security/notices/USN-3317-1","https://www.cve.org/CVERecord?id=CVE-2017-9468"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864400"],"patches":{"irssi":["upstream: https://github.com/irssi/irssi/commit/528f51bfbe5c65c5b24546faa244009dd5b3c586"]},"tags":{},"packages":[{"name":"irssi","source":"https://ubuntu.com/security/cve?package=irssi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=irssi","debian":"https://tracker.debian.org/pkg/irssi","statuses":[{"release_codename":"trusty","status":"released","description":"0.8.15-5ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.8.19-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.8.19-1ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.8.20-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3317-1"],"notices":[{"id":"USN-3317-1","title":"Irssi vulnerabilities","summary":"Irssi could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"After a standard system update you need to restart Irssi to make all the\nnecessary changes.\n","references":[],"published":"2017-06-12T12:30:47.783054","description":"It was discovered that Irssi incorrectly handled certain DCC messages. A\nmalicious IRC server could use this issue to cause Irssi to crash,\nresulting in a denial of service. (CVE-2017-9468)\n\nJoseph Bisch discovered that Irssi incorrectly handled receiving\nincorrectly quoted DCC files. A remote attacker could possibly use this\nissue to cause Irssi to crash, resulting in a denial of service.\n(CVE-2017-9469)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"irssi","version":"0.8.15-5ubuntu3.2","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.15-5ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.2","pocket":"security"},{"name":"irssi-dev","version":"0.8.15-5ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.15-5ubuntu3.2","pocket":"security"}],"xenial":[{"name":"irssi","version":"0.8.19-1ubuntu1.4","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.4","pocket":"security"},{"name":"irssi-dev","version":"0.8.19-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu1.4","pocket":"security"}],"yakkety":[{"name":"irssi","version":"0.8.19-1ubuntu2.2","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.19-1ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.19-1ubuntu2.2"}],"zesty":[{"name":"irssi","version":"0.8.20-2ubuntu2.1","description":"terminal based IRC client","is_source":true},{"name":"irssi","version":"0.8.20-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/irssi","version_link":"https://launchpad.net/ubuntu/+source/irssi/0.8.20-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2017-9468","CVE-2017-9469"]}]},{"id":"CVE-2017-9461","published":"2017-06-06T00:00:00","updated_at":"2025-08-25T22:41:43.751119+00:00","description":"\nsmbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service\nvulnerability (fd_open_atomic infinite loop with high CPU usage and memory\nconsumption) due to wrongly handling dangling symlinks.","ubuntu_description":"","notes":[{"author":"leosilva","note":"precise/esm hasn't the code affect."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3348-1","https://www.cve.org/CVERecord?id=CVE-2017-9461"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864291","https://bugzilla.samba.org/show_bug.cgi?id=12572"],"patches":{"samba":["upstream: https://git.samba.org/?p=samba.git;a=commit;h=10c3e3923022485c720f322ca4f0aca5d7501310","upstream: https://git.samba.org/?p=samba.git;a=commit;h=f289980e5531372dd63ec483e265e48efb8cf207"]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"artful","status":"not-affected","description":"2:4.5.8+dfsg-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.14.04.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.5.8","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:4.4.5+dfsg-2ubuntu5.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.16.04.8","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:4.5.8+dfsg-0ubuntu0.17.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3348-1"],"notices":[{"id":"USN-3348-1","title":"Samba vulnerability","summary":"Samba could be made to hang if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-05T17:53:18.876179","description":"It was discovered that Samba incorrectly handled dangling symlinks. A\nremote attacker could possibly use this issue to cause Samba to hang,\nresulting in a denial of service. This issue only applied to Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2017-9461)\n\nIn addition, this update fixes a regression introduced by USN-3267-1\nthat caused Samba to incorrectly handle non-wide symlinks to directories.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libpam-smbpass","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libsmbsharemodes-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libsmbsharemodes0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-doc","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.9","pocket":"security"}],"xenial":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.8","pocket":"security"}],"yakkety":[{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.7","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:4.4.5+dfsg-2ubuntu5.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.4.5+dfsg-2ubuntu5.7"}],"zesty":[{"name":"samba","version":"2:4.5.8+dfsg-0ubuntu0.17.04.3","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"samba","version":"2:4.5.8+dfsg-0ubuntu0.17.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.5.8+dfsg-0ubuntu0.17.04.3"}]},"type":"USN","cves_ids":["CVE-2017-9461"]}]},{"id":"CVE-2017-7515","published":"2017-06-06T00:00:00","updated_at":"2025-08-25T22:37:48.884672+00:00","description":"\npoppler through version 0.55.0 is vulnerable to an uncontrolled recursion\nin pdfunite resulting into potential denial-of-service.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"possibly only affects CLI tool, so may not have any security\nimpact."}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3350-1","https://www.cve.org/CVERecord?id=CVE-2017-7515"],"bugs":["https://bugs.freedesktop.org/show_bug.cgi?id=101208"],"patches":{"poppler":["upstream: https://cgit.freedesktop.org/poppler/poppler/commit/poppler/PDFDoc.cc?id=771c82623e8e1e0c92b8ca6f7c2b8a81ccbb60d3"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.44.0-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.48.0-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3350-1"],"notices":[{"id":"USN-3350-1","title":"poppler vulnerabilities","summary":"poppler could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-07T14:45:36.232540","description":"Aleksandar Nikolic discovered that poppler incorrectly handled JPEG 2000\nimages. If a user or automated system were tricked into opening a crafted\nPDF file, an attacker could cause a denial of service or possibly execute\narbitrary code with privileges of the user invoking the program.\n(CVE-2017-2820)\n\nJiaqi Peng discovered that the poppler pdfunite tool incorrectly parsed\ncertain malformed PDF documents. If a user or automated system were tricked\ninto opening a crafted PDF file, an attacker could cause poppler to crash,\nresulting in a denial of service. (CVE-2017-7511)\n\nIt was discovered that the poppler pdfunite tool incorrectly parsed certain\nmalformed PDF documents. If a user or automated system were tricked into\nopening a crafted PDF file, an attacker could cause poppler to hang,\nresulting in a denial of service. (CVE-2017-7515)\n\nIt was discovered that poppler incorrectly handled JPEG 2000 images. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause cause poppler to crash, resulting in a denial of\nservice. (CVE-2017-9083)\n\nIt was discovered that poppler incorrectly handled memory when processing\nPDF documents. If a user or automated system were tricked into opening a\ncrafted PDF file, an attacker could cause poppler to consume resources,\nresulting in a denial of service. (CVE-2017-9406, CVE-2017-9408)\n\nAlberto Garcia, Francisco Oca, and Suleman Ali discovered that the poppler\npdftocairo tool incorrectly parsed certain malformed PDF documents. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause poppler to crash, resulting in a denial of service.\n(CVE-2017-9775)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.5","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"}],"yakkety":[{"name":"poppler","version":"0.44.0-3ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler61","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"poppler-utils","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"}],"zesty":[{"name":"poppler","version":"0.48.0-2ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler64","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"poppler-utils","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2017-2820","CVE-2017-7511","CVE-2017-7515","CVE-2017-9083","CVE-2017-9406","CVE-2017-9408","CVE-2017-9775"]}]},{"id":"CVE-2017-5664","published":"2017-06-06T00:00:00","updated_at":"2025-08-18T17:06:59.260611+00:00","description":"\nThe error page mechanism of the Java Servlet Specification requires that,\nwhen an error occurs and an error page is configured for the error that\noccurred, the original request and response are forwarded to the error\npage. This means that the request is presented to the error page with the\noriginal HTTP method. If the error page is a static file, expected\nbehaviour is to serve content of the file as if processing a GET request,\nregardless of the actual HTTP method. The Default Servlet in Apache Tomcat\n9.0.0.M1 to 9.0.0.M20, 8.5.0 to 8.5.14, 8.0.0.RC1 to 8.0.43 and 7.0.0 to\n7.0.77 did not do this. Depending on the original request this could lead\nto unexpected and undesirable results for static error pages including, if\nthe DefaultServlet is configured to permit writes, the replacement or\nremoval of the custom error page. Notes for other user provided error\npages: (1) Unless explicitly coded otherwise, JSPs ignore the HTTP method.\nJSPs used as error pages must must ensure that they handle any error\ndispatch as a GET request, regardless of the actual method. (2) By default,\nthe response generated by a Servlet does depend on the HTTP method. Custom\nServlets used as error pages must ensure that they handle any error\ndispatch as a GET request, regardless of the actual method.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.apache.org/thread.html/a42c48e37398d76334e17089e43ccab945238b8b7896538478d76066@%3Cannounce.tomcat.apache.org%3E","http://apt.inguza.net/wheezy-security/tomcat/tomcat8-CVE-2017-5664.patch","https://ubuntu.com/security/notices/USN-3519-1","https://www.cve.org/CVERecord?id=CVE-2017-5664"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802312"],"patches":{"tomcat7":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1793471","upstream: https://svn.apache.org/viewvc?view=revision&revision=1793491"],"tomcat6":[],"tomcat8":["upstream: https://svn.apache.org/viewvc?view=revision&revision=1793470","upstream: https://svn.apache.org/viewvc?view=revision&revision=1793489"]},"tags":{},"packages":[{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"7.0.78-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"7.0.78-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"7.0.78-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7.0.52-1ubuntu0.13","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.78","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"6.0.45+dfsg-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.0.41-3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"8.5.21-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8.5.21-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8.5.21-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.5.15","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8.0.32-1ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8.0.38-2ubuntu2.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3519-1"],"notices":[{"id":"USN-3519-1","title":"Tomcat vulnerabilities","summary":"Several security issues were fixed in Tomcat.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-01-08T15:38:49.695901","description":"It was discovered that Tomcat incorrectly handled certain pipelined\nrequests when sendfile was used. A remote attacker could use this issue to\nobtain wrong responses possibly containing sensitive information.\n(CVE-2017-5647)\n\nIt was discovered that Tomcat incorrectly used the appropriate facade\nobject. A malicious application could possibly use this to bypass Security\nManager restrictions. (CVE-2017-5648)\n\nIt was discovered that Tomcat incorrectly handled error pages. A remote\nattacker could possibly use this issue to replace or remove the custom\nerror page. (CVE-2017-5664)\n\nIt was discovered that Tomcat incorrectly handled the CORS filter. A remote\nattacker could possibly use this issue to perform cache poisoning.\n(CVE-2017-7674)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tomcat7","version":"7.0.52-1ubuntu0.13","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.0-java","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"libservlet3.0-java-doc","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"libtomcat7-java","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"tomcat7","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"tomcat7-admin","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"tomcat7-common","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"tomcat7-docs","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"tomcat7-examples","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"},{"name":"tomcat7-user","version":"7.0.52-1ubuntu0.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat7","version_link":"https://launchpad.net/ubuntu/+source/tomcat7/7.0.52-1ubuntu0.13","pocket":"security"}],"xenial":[{"name":"tomcat8","version":"8.0.32-1ubuntu1.5","description":"Servlet and JSP engine","is_source":true},{"name":"libservlet3.1-java","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"libservlet3.1-java-doc","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"libtomcat8-java","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"tomcat8","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"tomcat8-admin","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"tomcat8-common","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"tomcat8-docs","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"tomcat8-examples","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"},{"name":"tomcat8-user","version":"8.0.32-1ubuntu1.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.32-1ubuntu1.5","pocket":"security"}],"zesty":[{"name":"tomcat8","version":"8.0.38-2ubuntu2.2","description":"Servlet and JSP engine","is_source":true},{"name":"libtomcat8-java","version":"8.0.38-2ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.38-2ubuntu2.2"},{"name":"tomcat8","version":"8.0.38-2ubuntu2.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":"https://launchpad.net/ubuntu/+source/tomcat8/8.0.38-2ubuntu2.2"}]},"type":"USN","cves_ids":["CVE-2017-5647","CVE-2017-5648","CVE-2017-5664","CVE-2017-7674"]}]},{"id":"CVE-2017-9438","published":"2017-06-05T17:29:00","updated_at":"2026-03-09T18:04:00.139033+00:00","description":"\nlibyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to\ncause a denial of service (stack consumption) via a crafted rule (involving\nhex strings) that is mishandled in the _yr_re_emit function, a different\nvulnerability than CVE-2017-9304.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/VirusTotal/yara/issues/674","https://github.com/VirusTotal/yara/commit/10e8bd3071677dd1fa76beeef4bc2fc427cea5e7","https://www.cve.org/CVERecord?id=CVE-2017-9438","https://ubuntu.com/security/notices/USN-8080-1"],"bugs":[""],"patches":{"yara":["upstream: https://github.com/VirusTotal/yara/commit/10e8bd3071677dd1fa76beeef4bc2fc427cea5e7"]},"tags":{},"packages":[{"name":"yara","source":"https://ubuntu.com/security/cve?package=yara","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=yara","debian":"https://tracker.debian.org/pkg/yara","statuses":[{"release_codename":"jammy","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.4.0+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8080-1"],"notices":[{"id":"USN-8080-1","title":"YARA vulnerabilities","summary":"Several security issues were fixed in YARA.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-09T16:06:04.323041","description":"Kamil Frankowicz discovered that a number of YARA's functions\ngenerated memory exceptions when processing specially crafted\nrules or files. A remote attacker could possibly use these\nissues to cause YARA to crash, resulting in a denial of\nservice. These issues only affected Ubuntu 16.04 LTS.\n(CVE-2016-10211, CVE-2017-5923, CVE-2017-5924, CVE-2017-8294,\nCVE-2017-8929, CVE-2017-9304, CVE-2017-9438, CVE-2017-9465)\n\nJurriaan Bremer discovered that YARA's yr_object_array_set_limit()\nfunction could result in a heap buffer overflow when scanning\nspecially crafted .NET files. A remote attacker could possibly use\nthis issue to cause YARA to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2017-11328)\n\nIt was discovered that YARA's yr_execute_code() function could\ncause an out-of-bounds read or write when parsing specially crafted\ncompiled rule files. A remote attacker could possibly use these\nissues to cause YARA to crash, resulting in a denial of service.\nThese issues only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2018-12034, CVE-2018-12035)\n\nIt was discovered that YARA's virtual machine could be escaped in\ncertain instances. A remote attacker could possibly use these issues\nto execute arbitrary code. These issues only affected Ubuntu 16.04\nLTS and Ubuntu 18.04 LTS. (CVE-2018-19974, CVE-2018-19975,\nCVE-2018-19976)\n\nIt was discovered that YARA's macho_parse_file() function would\ngenerate an out-of-bounds memory access error when parsing a\nspecially crafted Mach-O file. A remote attacker could possibly use\nthis issue to cause YARA to crash, resulting in a denial of service,\nor execute arbitrary code. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2019-19648)\n\nIt was discovered that YARA's macho.c implementation contained several\noverflow reads, which could be triggered when parsing specially\ncrafted Mach-O files. A remote attacker could possibly use this issue\nto cause YARA to crash, resulting in a denial of service, or to learn\nsensitive information. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2021-3402)\n\nIt was discovered that YARA's yr_set_configuration() function could\ntrigger a buffer overflow when parsing specially crafted rules. A\nremote attacker could possibly use this issue to cause YARA to crash,\nresulting in a denial of service. This issue only affected Ubuntu\n18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-45429)","is_hidden":false,"release_packages":{"bionic":[{"name":"yara","version":"3.7.1-1ubuntu2+esm1","description":"The pattern matching swiss knife for malware researchers","is_source":true},{"name":"libyara-dev","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"libyara3","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara-doc","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"yara","version":"3.9.0-1ubuntu0.1~esm1","description":"The pattern matching swiss knife for malware researchers","is_source":true},{"name":"libyara-dev","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"libyara3","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara-doc","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","description":"The pattern matching swiss knife for malware researchers","is_source":true},{"name":"libyara-dev","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"libyara3","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"python-yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"python3-yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara-doc","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-9304","CVE-2017-9465","CVE-2018-19976","CVE-2019-19648","CVE-2017-9438","CVE-2018-19975","CVE-2018-12035","CVE-2021-45429","CVE-2016-10211","CVE-2017-11328","CVE-2021-3402","CVE-2017-8294","CVE-2018-19974","CVE-2018-12034","CVE-2017-8929","CVE-2017-5923","CVE-2017-5924"]}]},{"id":"CVE-2017-9435","published":"2017-06-05T14:29:00","updated_at":"2025-08-26T12:02:23.808190+00:00","description":"\nDolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in\nuser/index.php (search_supervisor and search_statut parameters).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/Dolibarr/dolibarr/commit/70636cc59ffa1ffbc0ce3dba315d7d9b837aad04","https://github.com/Dolibarr/dolibarr/blob/develop/ChangeLog","https://www.cve.org/CVERecord?id=CVE-2017-9435"],"bugs":[""],"patches":{"dolibarr":["upstream: https://github.com/Dolibarr/dolibarr/commit/70636cc59ffa1ffbc0ce3dba315d7d9b837aad04"]},"tags":{},"packages":[{"name":"dolibarr","source":"https://ubuntu.com/security/cve?package=dolibarr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dolibarr","debian":"https://tracker.debian.org/pkg/dolibarr","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9434","published":"2017-06-05T14:29:00","updated_at":"2025-08-25T22:41:38.446694+00:00","description":"\nCrypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read\nvulnerability in zinflate.cpp in the Inflator filter.","ubuntu_description":"\nIt was discovered that Crypto++ mishandled certain input. An attacker could use\nthis vulnerability to leak potentially sensitive information.","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/weidai11/cryptopp/issues/414","https://github.com/weidai11/cryptopp/commit/07dbcc3d9644b18e05c1776db2a57fe04d780965","https://www.cve.org/CVERecord?id=CVE-2017-9434","https://ubuntu.com/security/notices/USN-4827-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864214"],"patches":{"libcrypto++":[]},"tags":{},"packages":[{"name":"libcrypto++","source":"https://ubuntu.com/security/cve?package=libcrypto++","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libcrypto++","debian":"https://tracker.debian.org/pkg/libcrypto++","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.6.4-7","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"5.6.4-8","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.6.1-9ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.6.1-6+deb8u3ubuntu0.1~esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-4827-1"],"notices":[{"id":"USN-4827-1","title":"Crypto++ vulnerability","summary":"Crypto++ could be made to expose sensitive information if it received\nspecially crafted input.","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T22:10:03.273221","description":"It was discovered that Crypto++ mishandled certain input. An attacker could\nuse this vulnerability to leak potentially sensitive information.","is_hidden":false,"release_packages":{"trusty":[{"name":"libcrypto++","version":"5.6.1-6+deb8u3ubuntu0.1~esm1","description":"General purpose cryptographic library for C++","is_source":true},{"name":"libcrypto++-dev","version":"5.6.1-6+deb8u3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-infra"},{"name":"libcrypto++-doc","version":"5.6.1-6+deb8u3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-infra"},{"name":"libcrypto++-utils","version":"5.6.1-6+deb8u3ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-infra"},{"name":"libcrypto++9","version":"5.6.1-6+deb8u3ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libcrypto++","version":"5.6.1-9ubuntu0.1+esm1","description":"General purpose cryptographic library for C++","is_source":true},{"name":"libcrypto++9v5","version":"5.6.1-9ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-apps"},{"name":"libcrypto++-dev","version":"5.6.1-9ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-apps"},{"name":"libcrypto++-doc","version":"5.6.1-9ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-apps"},{"name":"libcrypto++-utils","version":"5.6.1-9ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libcrypto++","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-9434"]}]},{"id":"CVE-2017-9430","published":"2017-06-05T11:29:00","updated_at":"2025-07-11T07:39:09.739671+00:00","description":"\nStack-based buffer overflow in dnstracer through 1.9 allows attackers to\ncause a denial of service (application crash) or possibly have unspecified\nother impact via a command line with a long name argument that is\nmishandled in a strcpy call for argv[0]. An example threat model is a web\napplication that launches dnstracer with an untrusted name string.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://cxsecurity.com/issue/WLB-2017060030","https://www.cve.org/CVERecord?id=CVE-2017-9430"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/dnstracer/+bug/1734279"],"patches":{"dnstracer":[]},"tags":{},"packages":[{"name":"dnstracer","source":"https://ubuntu.com/security/cve?package=dnstracer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dnstracer","debian":"https://tracker.debian.org/pkg/dnstracer","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9432","published":"2017-06-05T03:29:00","updated_at":"2025-08-25T22:41:38.446694+00:00","description":"\nDocument Liberation Project libstaroffice before 2017-04-07 has an\nout-of-bounds write caused by a stack-based buffer overflow related to the\nDatabaseName::read function in lib/StarWriterStruct.cxx.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1029","https://github.com/fosnola/libstaroffice/commit/2d6253c7a692a3d92785dd990fce7256ea05e794","https://www.cve.org/CVERecord?id=CVE-2017-9432"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864207"],"patches":{"libstaroffice":["upstream: https://github.com/fosnola/libstaroffice/commit/2d6253c7a692a3d92785dd990fce7256ea05e794"]},"tags":{},"packages":[{"name":"libstaroffice","source":"https://ubuntu.com/security/cve?package=libstaroffice","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libstaroffice","debian":"https://tracker.debian.org/pkg/libstaroffice","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.0.5-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.0.5-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.0.3-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9431","published":"2017-06-05T03:29:00","updated_at":"2025-08-25T22:41:38.446694+00:00","description":"\nGoogle gRPC before 2017-04-05 has an out-of-bounds write caused by a\nheap-based buffer overflow related to core/lib/iomgr/error.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/grpc/grpc/pull/10492","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1018","https://www.cve.org/CVERecord?id=CVE-2017-9431"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864210"],"patches":{"grpc":["upstream: https://github.com/grpc/grpc/commit/c6ec1155d026c91b1badb07ef1605bb747cff064"]},"tags":{},"packages":[{"name":"grpc","source":"https://ubuntu.com/security/cve?package=grpc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=grpc","debian":"https://tracker.debian.org/pkg/grpc","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.3.2-0.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.2-0.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.2-0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.2-0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9440","published":"2017-06-05T00:00:00","updated_at":"2025-08-25T22:41:38.446694+00:00","description":"\nIn ImageMagick 7.0.5-5, a memory leak was found in the function\nReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of\nservice via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0053-CVE-2017-9440.patch"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3363-1","https://www.cve.org/CVERecord?id=CVE-2017-9440"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/462","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864273"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/c2be129c25763680afeca59f4de5d6d4240ca2cf"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.8","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8:6.9.7.4+dfsg-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-3363-1"],"notices":[{"id":"USN-3363-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-24T16:42:44.364124","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"}],"zesty":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2017-10928","CVE-2017-11141","CVE-2017-11170","CVE-2017-11188","CVE-2017-11352","CVE-2017-11360","CVE-2017-11447","CVE-2017-11448","CVE-2017-11449","CVE-2017-11450","CVE-2017-11478","CVE-2017-9261","CVE-2017-9262","CVE-2017-9405","CVE-2017-9407","CVE-2017-9409","CVE-2017-9439","CVE-2017-9440","CVE-2017-9501"]}]}],"offset":56720,"limit":20,"total_results":79316}