{"cves":[{"id":"CVE-2017-9408","published":"2017-06-02T00:00:00","updated_at":"2025-08-25T22:41:33.552062+00:00","description":"\nIn Poppler 0.54.0, a memory leak vulnerability was found in the function\nObject::initArray in Object.cc, which allows attackers to cause a denial of\nservice via a crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3350-1","https://www.cve.org/CVERecord?id=CVE-2017-9408"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864009","https://bugs.freedesktop.org/show_bug.cgi?id=100776"],"patches":{"poppler":["upstream: https://cgit.freedesktop.org/poppler/poppler/commit/?id=b21b041f7948680c03109f0c404400a9dbc4544c"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.55","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.44.0-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.48.0-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3350-1"],"notices":[{"id":"USN-3350-1","title":"poppler vulnerabilities","summary":"poppler could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-07T14:45:36.232540","description":"Aleksandar Nikolic discovered that poppler incorrectly handled JPEG 2000\nimages. If a user or automated system were tricked into opening a crafted\nPDF file, an attacker could cause a denial of service or possibly execute\narbitrary code with privileges of the user invoking the program.\n(CVE-2017-2820)\n\nJiaqi Peng discovered that the poppler pdfunite tool incorrectly parsed\ncertain malformed PDF documents. If a user or automated system were tricked\ninto opening a crafted PDF file, an attacker could cause poppler to crash,\nresulting in a denial of service. (CVE-2017-7511)\n\nIt was discovered that the poppler pdfunite tool incorrectly parsed certain\nmalformed PDF documents. If a user or automated system were tricked into\nopening a crafted PDF file, an attacker could cause poppler to hang,\nresulting in a denial of service. (CVE-2017-7515)\n\nIt was discovered that poppler incorrectly handled JPEG 2000 images. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause cause poppler to crash, resulting in a denial of\nservice. (CVE-2017-9083)\n\nIt was discovered that poppler incorrectly handled memory when processing\nPDF documents. If a user or automated system were tricked into opening a\ncrafted PDF file, an attacker could cause poppler to consume resources,\nresulting in a denial of service. (CVE-2017-9406, CVE-2017-9408)\n\nAlberto Garcia, Francisco Oca, and Suleman Ali discovered that the poppler\npdftocairo tool incorrectly parsed certain malformed PDF documents. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause poppler to crash, resulting in a denial of service.\n(CVE-2017-9775)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.5","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"}],"yakkety":[{"name":"poppler","version":"0.44.0-3ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler61","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"poppler-utils","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"}],"zesty":[{"name":"poppler","version":"0.48.0-2ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler64","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"poppler-utils","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2017-2820","CVE-2017-7511","CVE-2017-7515","CVE-2017-9083","CVE-2017-9406","CVE-2017-9408","CVE-2017-9775"]}]},{"id":"CVE-2017-9407","published":"2017-06-02T00:00:00","updated_at":"2025-08-25T22:41:33.552062+00:00","description":"\nIn ImageMagick 7.0.5-5, the ReadPALMImage function in palm.c allows\nattackers to cause a denial of service (memory leak) via a crafted file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reproducer in github issue"},{"author":"mdeslaur","note":"This is 0050-CVE-2017-9407-the-ReadPALMImage-function-in-palm.c-a.patch"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3363-1","https://www.cve.org/CVERecord?id=CVE-2017-9407"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/459","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864089"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/3a7e63bc27e3e84cec4617125fa7641d77b90e65"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.8","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8:6.9.7.4+dfsg-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-3363-1"],"notices":[{"id":"USN-3363-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-24T16:42:44.364124","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"}],"zesty":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2017-10928","CVE-2017-11141","CVE-2017-11170","CVE-2017-11188","CVE-2017-11352","CVE-2017-11360","CVE-2017-11447","CVE-2017-11448","CVE-2017-11449","CVE-2017-11450","CVE-2017-11478","CVE-2017-9261","CVE-2017-9262","CVE-2017-9405","CVE-2017-9407","CVE-2017-9409","CVE-2017-9439","CVE-2017-9440","CVE-2017-9501"]}]},{"id":"CVE-2017-9406","published":"2017-06-02T00:00:00","updated_at":"2025-08-25T22:41:33.552062+00:00","description":"\nIn Poppler 0.54.0, a memory leak vulnerability was found in the function\ngmalloc in gmem.cc, which allows attackers to cause a denial of service via\na crafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3350-1","https://www.cve.org/CVERecord?id=CVE-2017-9406"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864010","https://bugs.freedesktop.org/show_bug.cgi?id=100775"],"patches":{"poppler":["upstream: https://cgit.freedesktop.org/poppler/poppler/commit/?id=278439531b13b0b047dbe3a75aa3f1b3407c8bd4"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.55","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.44.0-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.48.0-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3350-1"],"notices":[{"id":"USN-3350-1","title":"poppler vulnerabilities","summary":"poppler could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-07T14:45:36.232540","description":"Aleksandar Nikolic discovered that poppler incorrectly handled JPEG 2000\nimages. If a user or automated system were tricked into opening a crafted\nPDF file, an attacker could cause a denial of service or possibly execute\narbitrary code with privileges of the user invoking the program.\n(CVE-2017-2820)\n\nJiaqi Peng discovered that the poppler pdfunite tool incorrectly parsed\ncertain malformed PDF documents. If a user or automated system were tricked\ninto opening a crafted PDF file, an attacker could cause poppler to crash,\nresulting in a denial of service. (CVE-2017-7511)\n\nIt was discovered that the poppler pdfunite tool incorrectly parsed certain\nmalformed PDF documents. If a user or automated system were tricked into\nopening a crafted PDF file, an attacker could cause poppler to hang,\nresulting in a denial of service. (CVE-2017-7515)\n\nIt was discovered that poppler incorrectly handled JPEG 2000 images. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause cause poppler to crash, resulting in a denial of\nservice. (CVE-2017-9083)\n\nIt was discovered that poppler incorrectly handled memory when processing\nPDF documents. If a user or automated system were tricked into opening a\ncrafted PDF file, an attacker could cause poppler to consume resources,\nresulting in a denial of service. (CVE-2017-9406, CVE-2017-9408)\n\nAlberto Garcia, Francisco Oca, and Suleman Ali discovered that the poppler\npdftocairo tool incorrectly parsed certain malformed PDF documents. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause poppler to crash, resulting in a denial of service.\n(CVE-2017-9775)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.5","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"}],"yakkety":[{"name":"poppler","version":"0.44.0-3ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler61","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"poppler-utils","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"}],"zesty":[{"name":"poppler","version":"0.48.0-2ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler64","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"poppler-utils","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2017-2820","CVE-2017-7511","CVE-2017-7515","CVE-2017-9083","CVE-2017-9406","CVE-2017-9408","CVE-2017-9775"]}]},{"id":"CVE-2017-9405","published":"2017-06-02T00:00:00","updated_at":"2025-08-25T22:41:33.552062+00:00","description":"\nIn ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows\nattackers to cause a denial of service (memory leak) via a crafted file.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"reproducer in git bug report"},{"author":"mdeslaur","note":"This is 0051-CVE-2017-9405-the-ReadICONImage-function-in-icon.c-4.patch"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3363-1","https://www.cve.org/CVERecord?id=CVE-2017-9405"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/457","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=864087"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/fbb14283450d3001403e7d9725566dd4fb2c3bb5"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.8","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8:6.9.7.4+dfsg-3ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.8","component":null,"pocket":"security"}]}],"notices_ids":["USN-3363-1"],"notices":[{"id":"USN-3363-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-24T16:42:44.364124","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"}],"zesty":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2017-10928","CVE-2017-11141","CVE-2017-11170","CVE-2017-11188","CVE-2017-11352","CVE-2017-11360","CVE-2017-11447","CVE-2017-11448","CVE-2017-11449","CVE-2017-11450","CVE-2017-11478","CVE-2017-9261","CVE-2017-9262","CVE-2017-9405","CVE-2017-9407","CVE-2017-9409","CVE-2017-9439","CVE-2017-9440","CVE-2017-9501"]}]},{"id":"CVE-2017-9404","published":"2017-06-02T00:00:00","updated_at":"2025-08-25T22:41:33.552062+00:00","description":"\nIn LibTIFF 4.0.7, a memory leak vulnerability was found in the function\nOJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers\nto cause a denial of service via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3602-1","https://www.cve.org/CVERecord?id=CVE-2017-9404"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2688","http://bugzilla.maptools.org/show_bug.cgi?id=2670","http://bugzilla.maptools.org/show_bug.cgi?id=2659"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/2ea32f7372b65c24b2816f11c04bf59b5090d05b","upstream: https://github.com/vadz/libtiff/commit/e9bd1b06fe25219cf0873fca70e46f01843fd9f4","upstream: https://github.com/vadz/libtiff/commit/8283e4d1b7e53340684d12932880cbcbaf23a8c1"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.8-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.8-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3602-1"],"notices":[{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2017-9403","published":"2017-06-02T00:00:00","updated_at":"2025-08-25T22:41:33.552062+00:00","description":"\nIn LibTIFF 4.0.7, a memory leak vulnerability was found in the function\nTIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to\ncause a denial of service via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this will not be fixed in precise/esm"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3602-1","https://www.cve.org/CVERecord?id=CVE-2017-9403"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2689"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/fb3dc46a2fcf6197ff3b93fc76f0c37fddc0333b"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.8-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.8-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3602-1"],"notices":[{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2017-9334","published":"2017-06-01T05:29:00","updated_at":"2025-08-26T12:02:23.808190+00:00","description":"\nAn incorrect \"pair?\" check in the Scheme \"length\" procedure results in an\nunsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13,\nwhich allows an attacker to cause a denial of service by passing an\nimproper list to an application that calls \"length\" on it.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.nongnu.org/archive/html/chicken-announce/2017-05/msg00000.html","http://lists.nongnu.org/archive/html/chicken-hackers/2017-05/msg00099.html","https://www.cve.org/CVERecord?id=CVE-2017-9334"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863884"],"patches":{"chicken":[]},"tags":{},"packages":[{"name":"chicken","source":"https://ubuntu.com/security/cve?package=chicken","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chicken","debian":"https://tracker.debian.org/pkg/chicken","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12.0-0.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.12.0-0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9060","published":"2017-06-01T00:00:00","updated_at":"2025-08-25T22:40:45.592226+00:00","description":"\nMemory leak in the virtio_gpu_set_scanout function in\nhw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS\nusers to cause a denial of service (memory consumption) via a large number\nof \"VIRTIO_GPU_CMD_SET_SCANOUT:\" commands.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3414-1","https://www.cve.org/CVERecord?id=CVE-2017-9060"],"bugs":[""],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=dd248ed7e204ee8a1873914e02b8b526e8f1b80d"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:2.8+dfsg-3ubuntu2.4","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3414-1"],"notices":[{"id":"USN-3414-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-09-13T11:58:25.128173","description":"Leo Gaspard discovered that QEMU incorrectly handled VirtFS access control.\nA guest attacker could use this issue to elevate privileges inside the\nguest. (CVE-2017-7493)\n\nLi Qiang discovered that QEMU incorrectly handled VMWare PVSCSI emulation.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto consume resources or crash, resulting in a denial of service.\n(CVE-2017-8112)\n\nIt was discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2 Host\nBus Adapter emulation support. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service, or\npossibly to obtain sensitive host memory. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 17.04. (CVE-2017-8380)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to consume\nresources and crash, resulting in a denial of service. This issue only\naffected Ubuntu 17.04. (CVE-2017-9060)\n\nLi Qiang discovered that QEMU incorrectly handled the e1000e device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\nhang, resulting in a denial of service. This issue only affected Ubuntu\n17.04. (CVE-2017-9310)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI emulation\nsupport. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-9330)\n\nLi Qiang discovered that QEMU incorrectly handled IDE AHCI emulation\nsupport. A privileged attacker inside the guest could use this issue to\ncause QEMU to consume resources and crash, resulting in a denial of\nservice. (CVE-2017-9373)\n\nLi Qiang discovered that QEMU incorrectly handled USB EHCI emulation\nsupport. A privileged attacker inside the guest could use this issue to\ncause QEMU to consume resources and crash, resulting in a denial of\nservice. (CVE-2017-9374)\n\nLi Qiang discovered that QEMU incorrectly handled USB xHCI emulation\nsupport. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-9375)\n\nZhangyanyu discovered that QEMU incorrectly handled MegaRAID SAS 8708EM2\nHost Bus Adapter emulation support. A privileged attacker inside the guest\ncould use this issue to cause QEMU to crash, resulting in a denial of\nservice. (CVE-2017-9503)\n\nIt was discovered that the QEMU qemu-nbd server incorrectly handled\ninitialization. A remote attacker could use this issue to cause the server\nto crash, resulting in a denial of service. (CVE-2017-9524)\n\nIt was discovered that the QEMU qemu-nbd server incorrectly handled\nsignals. A remote attacker could use this issue to cause the server to\ncrash, resulting in a denial of service. (CVE-2017-10664)\n\nLi Qiang discovered that the QEMU USB redirector incorrectly handled\nlogging debug messages. An attacker inside the guest could use this issue\nto cause QEMU to crash, resulting in a denial of service. (CVE-2017-10806)\n\nAnthony Perard discovered that QEMU incorrectly handled Xen block-interface\nresponses. An attacker inside the guest could use this issue to cause QEMU\nto leak contents of host memory. (CVE-2017-10911)\n\nReno Robert discovered that QEMU incorrectly handled certain DHCP options\nstrings. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-11434)\n\nRyan Salsamendi discovered that QEMU incorrectly handled empty CDROM device\ndrives. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 16.04 LTS and Ubuntu 17.04. (CVE-2017-12809)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.35","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.35","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.35","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.15","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.15","pocket":"security"}],"zesty":[{"name":"qemu","version":"1:2.8+dfsg-3ubuntu2.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-aarch64","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-arm","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-mips","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-misc","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-ppc","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-s390x","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-sparc","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"},{"name":"qemu-system-x86","version":"1:2.8+dfsg-3ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.8+dfsg-3ubuntu2.4"}]},"type":"USN","cves_ids":["CVE-2017-10664","CVE-2017-10806","CVE-2017-10911","CVE-2017-11434","CVE-2017-12809","CVE-2017-7493","CVE-2017-8112","CVE-2017-8380","CVE-2017-9060","CVE-2017-9310","CVE-2017-9330","CVE-2017-9373","CVE-2017-9374","CVE-2017-9375","CVE-2017-9503","CVE-2017-9524"]}]},{"id":"CVE-2017-6512","published":"2017-06-01T00:00:00","updated_at":"2025-08-25T22:36:26.245761+00:00","description":"\nRace condition in the rmtree and remove_tree functions in the File-Path\nmodule before 2.13 for Perl allows attackers to set the mode on arbitrary\nfiles via vectors involving directory-permission loosening logic.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://cpansearch.perl.org/src/JKEENAN/File-Path-2.13/Changes","https://ubuntu.com/security/notices/USN-3625-1","https://ubuntu.com/security/notices/USN-3625-2","https://www.cve.org/CVERecord?id=CVE-2017-6512"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863870","https://rt.cpan.org/Ticket/Display.html?id=121951"],"patches":{"perl":["upstream: https://github.com/jkeenan/File-Path/commit/e5ef95276ee8ad471c66ee574a5d42552b3a6af2"]},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"artful","status":"not-affected","description":"5.26.0-5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"5.18.2-2ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.24.1-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.22.1-9ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3625-1","USN-3625-2"],"notices":[{"id":"USN-3625-1","title":"Perl vulnerabilities","summary":"Several security issues were fixed in Perl.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-04-16T12:47:44.064056","description":"It was discovered that Perl incorrectly handled certain regular\nexpressions. An attacker could possibly use this issue to cause Perl to\nhang, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS. (CVE-2015-8853)\n\nIt was discovered that Perl incorrectly loaded libraries from the current\nworking directory. A local attacker could possibly use this issue to\nexecute arbitrary code. This issue only affected Ubuntu 14.04 LTS and\nUbuntu 16.04 LTS. (CVE-2016-6185)\n\nIt was discovered that Perl incorrectly handled the rmtree and remove_tree\nfunctions. A local attacker could possibly use this issue to set the mode\non arbitrary files. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2017-6512)\n\nBrian Carpenter discovered that Perl incorrectly handled certain regular\nexpressions. An attacker could use this issue to cause Perl to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue has only been addressed in Ubuntu 16.04 LTS and Ubuntu 17.10.\n(CVE-2018-6797)\n\nNguyen Duc Manh discovered that Perl incorrectly handled certain regular\nexpressions. An attacker could use this issue to cause Perl to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 17.10. (CVE-2018-6798)\n\nGwanYeong Kim discovered that Perl incorrectly handled certain data when\nusing the pack function. An attacker could use this issue to cause Perl to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2018-6913)\n","is_hidden":false,"release_packages":{"artful":[{"name":"perl","version":"5.26.0-8ubuntu1.1","description":"Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.26.0-8ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.26.0-8ubuntu1.1"}],"trusty":[{"name":"perl","version":"5.18.2-2ubuntu1.4","description":"Practical Extraction and Report Language","is_source":true},{"name":"libcgi-fast-perl","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"libperl-dev","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"libperl5.18","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"perl","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"perl-base","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"perl-debug","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"perl-doc","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"},{"name":"perl-modules","version":"5.18.2-2ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.4","pocket":"security"}],"xenial":[{"name":"perl","version":"5.22.1-9ubuntu0.3","description":"Practical Extraction and Report Language","is_source":true},{"name":"libperl-dev","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"},{"name":"libperl5.22","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"},{"name":"perl","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"},{"name":"perl-base","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"},{"name":"perl-debug","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"},{"name":"perl-doc","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"},{"name":"perl-modules-5.22","version":"5.22.1-9ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-8853","CVE-2016-6185","CVE-2017-6512","CVE-2018-6797","CVE-2018-6798","CVE-2018-6913"]},{"id":"USN-3625-2","title":"Perl vulnerabilities","summary":"Several security issues were fixed in Perl.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-04-17T21:00:14.517992","description":"USN-3625-1 fixed a vulnerability in Perl. This update provides\nthe corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that Perl incorrectly handled certain regular\n expressions. An attacker could possibly use this issue to cause Perl to\n hang, resulting in a denial of service. (CVE-2015-8853)\n\n It was discovered that Perl incorrectly loaded libraries from the current\n working directory. A local attacker could possibly use this issue to\n execute arbitrary code. (CVE-2016-6185)\n\n It was discovered that Perl incorrectly handled the rmtree and remove_tree\n functions. A local attacker could possibly use this issue to set the mode\n on arbitrary files. (CVE-2017-6512)\n\n GwanYeong Kim discovered that Perl incorrectly handled certain data when\n using the pack function. An attacker could use this issue to cause Perl to\n crash, resulting in a denial of service, or possibly execute arbitrary\n code. (CVE-2018-6913)\n","is_hidden":false,"release_packages":{"precise":[{"name":"perl","version":"5.14.2-6ubuntu2.7","description":"Practical Extraction and Report Language","is_source":true},{"name":"perl","version":"5.14.2-6ubuntu2.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/perl","version_link":"https://launchpad.net/ubuntu/+source/perl/5.14.2-6ubuntu2.7"}]},"type":"USN","cves_ids":["CVE-2015-8853","CVE-2016-6185","CVE-2017-6512","CVE-2018-6913"]}]},{"id":"CVE-2017-9304","published":"2017-05-31T04:29:00","updated_at":"2026-03-09T18:04:00.139033+00:00","description":"\nlibyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to\ncause a denial of service (stack consumption) via a crafted rule that is\nmishandled in the _yr_re_emit function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/VirusTotal/yara/issues/674","https://www.cve.org/CVERecord?id=CVE-2017-9304","https://ubuntu.com/security/notices/USN-8080-1"],"bugs":[""],"patches":{"yara":["upstream: https://github.com/VirusTotal/yara/commit/925bcf3c3b0a28b5b78e25d9efda5c0bf27ae699"]},"tags":{},"packages":[{"name":"yara","source":"https://ubuntu.com/security/cve?package=yara","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=yara","debian":"https://tracker.debian.org/pkg/yara","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.6.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.7.1-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.4.0+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8080-1"],"notices":[{"id":"USN-8080-1","title":"YARA vulnerabilities","summary":"Several security issues were fixed in YARA.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-09T16:06:04.323041","description":"Kamil Frankowicz discovered that a number of YARA's functions\ngenerated memory exceptions when processing specially crafted\nrules or files. A remote attacker could possibly use these\nissues to cause YARA to crash, resulting in a denial of\nservice. These issues only affected Ubuntu 16.04 LTS.\n(CVE-2016-10211, CVE-2017-5923, CVE-2017-5924, CVE-2017-8294,\nCVE-2017-8929, CVE-2017-9304, CVE-2017-9438, CVE-2017-9465)\n\nJurriaan Bremer discovered that YARA's yr_object_array_set_limit()\nfunction could result in a heap buffer overflow when scanning\nspecially crafted .NET files. A remote attacker could possibly use\nthis issue to cause YARA to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 16.04 LTS. (CVE-2017-11328)\n\nIt was discovered that YARA's yr_execute_code() function could\ncause an out-of-bounds read or write when parsing specially crafted\ncompiled rule files. A remote attacker could possibly use these\nissues to cause YARA to crash, resulting in a denial of service.\nThese issues only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2018-12034, CVE-2018-12035)\n\nIt was discovered that YARA's virtual machine could be escaped in\ncertain instances. A remote attacker could possibly use these issues\nto execute arbitrary code. These issues only affected Ubuntu 16.04\nLTS and Ubuntu 18.04 LTS. (CVE-2018-19974, CVE-2018-19975,\nCVE-2018-19976)\n\nIt was discovered that YARA's macho_parse_file() function would\ngenerate an out-of-bounds memory access error when parsing a\nspecially crafted Mach-O file. A remote attacker could possibly use\nthis issue to cause YARA to crash, resulting in a denial of service,\nor execute arbitrary code. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2019-19648)\n\nIt was discovered that YARA's macho.c implementation contained several\noverflow reads, which could be triggered when parsing specially\ncrafted Mach-O files. A remote attacker could possibly use this issue\nto cause YARA to crash, resulting in a denial of service, or to learn\nsensitive information. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2021-3402)\n\nIt was discovered that YARA's yr_set_configuration() function could\ntrigger a buffer overflow when parsing specially crafted rules. A\nremote attacker could possibly use this issue to cause YARA to crash,\nresulting in a denial of service. This issue only affected Ubuntu\n18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-45429)","is_hidden":false,"release_packages":{"bionic":[{"name":"yara","version":"3.7.1-1ubuntu2+esm1","description":"The pattern matching swiss knife for malware researchers","is_source":true},{"name":"libyara-dev","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"libyara3","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara-doc","version":"3.7.1-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"yara","version":"3.9.0-1ubuntu0.1~esm1","description":"The pattern matching swiss knife for malware researchers","is_source":true},{"name":"libyara-dev","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"libyara3","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara-doc","version":"3.9.0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","description":"The pattern matching swiss knife for malware researchers","is_source":true},{"name":"libyara-dev","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"libyara3","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"python-yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"python3-yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"},{"name":"yara-doc","version":"3.4.0+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/yara","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-9304","CVE-2017-9465","CVE-2018-19976","CVE-2019-19648","CVE-2017-9438","CVE-2018-19975","CVE-2018-12035","CVE-2021-45429","CVE-2016-10211","CVE-2017-11328","CVE-2021-3402","CVE-2017-8294","CVE-2018-19974","CVE-2018-12034","CVE-2017-8929","CVE-2017-5923","CVE-2017-5924"]}]},{"id":"CVE-2017-8782","published":"2017-05-31T04:29:00","updated_at":"2025-08-26T12:01:52.353126+00:00","description":"\nThe readString function in util/read.c and util/old/read.c in libming 0.4.8\nallows remote attackers to cause a denial of service via a large file that\nis mishandled by listswf, listaction, etc. This occurs because of an\ninteger overflow that leads to a memory allocation error.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://seclists.org/fulldisclosure/2017/May/106","https://www.cve.org/CVERecord?id=CVE-2017-8782"],"bugs":[""],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-1000367","published":"2017-05-30T15:00:00","updated_at":"2025-08-25T22:18:40.178769+00:00","description":"\nTodd Miller's sudo version 1.8.20 and earlier is vulnerable to an input\nvalidation (embedded spaces) in the get_process_ttyname() function\nresulting in information disclosure and command execution.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"code to parse /proc/pid/stat and walk /dev is not present\nin precise"}],"codename":null,"priority":"high","cvss3":6.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/05/30/16","https://www.sudo.ws/alerts/linux_tty.html","https://ubuntu.com/security/notices/USN-3304-1","https://www.cve.org/CVERecord?id=CVE-2017-1000367"],"bugs":[""],"patches":{"sudo":[]},"tags":{},"packages":[{"name":"sudo","source":"https://ubuntu.com/security/cve?package=sudo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sudo","debian":"https://tracker.debian.org/pkg/sudo","statuses":[{"release_codename":"trusty","status":"released","description":"1.8.9p5-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.16-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1.8.16-0ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1.8.19p1-1ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3304-1"],"notices":[{"id":"USN-3304-1","title":"Sudo vulnerability","summary":"Sudo could be made to overwrite files as the administrator.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-30T16:38:06.925280","description":"It was discovered that Sudo did not properly parse the contents of\n/proc/[pid]/stat when attempting to determine its controlling tty.\nA local attacker in some configurations could possibly use this to\noverwrite any file on the filesystem, bypassing intended permissions.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"sudo","version":"1.8.9p5-1ubuntu1.4","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo","version":"1.8.9p5-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.9p5-1ubuntu1.4","pocket":"security"},{"name":"sudo-ldap","version":"1.8.9p5-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.9p5-1ubuntu1.4","pocket":"security"}],"xenial":[{"name":"sudo","version":"1.8.16-0ubuntu1.4","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo","version":"1.8.16-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu1.4","pocket":"security"},{"name":"sudo-ldap","version":"1.8.16-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu1.4","pocket":"security"}],"yakkety":[{"name":"sudo","version":"1.8.16-0ubuntu3.2","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo","version":"1.8.16-0ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu3.2"},{"name":"sudo-ldap","version":"1.8.16-0ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.16-0ubuntu3.2"}],"zesty":[{"name":"sudo","version":"1.8.19p1-1ubuntu1.1","description":"Provide limited super user privileges to specific users","is_source":true},{"name":"sudo","version":"1.8.19p1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.19p1-1ubuntu1.1"},{"name":"sudo-ldap","version":"1.8.19p1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sudo","version_link":"https://launchpad.net/ubuntu/+source/sudo/1.8.19p1-1ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2017-1000367"]}]},{"id":"CVE-2017-9023","published":"2017-05-30T12:00:00","updated_at":"2025-08-25T22:40:40.921545+00:00","description":"\nThe ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types\nwhen the x509 plugin is enabled, which allows remote attackers to cause a\ndenial of service (infinite loop) via a crafted certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3301-1","https://www.cve.org/CVERecord?id=CVE-2017-9023"],"bugs":[""],"patches":{"strongswan":[]},"tags":{},"packages":[{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"trusty","status":"released","description":"5.1.2-0ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.3.5-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"5.3.5-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"5.5.1-1ubuntu3.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3301-1"],"notices":[{"id":"USN-3301-1","title":"strongSwan vulnerabilities","summary":"strongSwan could be made to crash or hang if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-30T13:03:09.563750","description":"It was discovered that the strongSwan gmp plugin incorrectly validated RSA\npublic keys. A remote attacker could use this issue to cause strongSwan to\ncrash, resulting in a denial of service. (CVE-2017-9022)\n\nIt was discovered that strongSwan incorrectly parsed ASN.1 CHOICE types. A\nremote attacker could use this issue to cause strongSwan to hang, resulting\nin a denial of service. (CVE-2017-9023)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"strongswan","version":"5.1.2-0ubuntu2.6","description":"IPsec VPN solution","is_source":true},{"name":"libstrongswan","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-ike","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-ikev1","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-ikev2","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-nm","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-af-alg","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-agent","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-attr-sql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-certexpire","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-coupling","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-curl","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-dhcp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-dnscert","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-dnskey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-duplicheck","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-aka","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-aka-3gpp2","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-dynamic","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-gtc","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-md5","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-mschapv2","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-peap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-radius","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-sim","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-sim-file","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-sim-pcsc","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-pseudonym","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-reauth","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-sql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-tls","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-tnc","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-ttls","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-error-notify","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-farp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-fips-prf","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-gcrypt","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-gmp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-ipseckey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-kernel-libipsec","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-ldap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-led","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-load-tester","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-lookip","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-mysql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-ntru","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-openssl","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-pgp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-pkcs11","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-pubkey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-radattr","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-soup","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-sql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-sqlite","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-sshkey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-systime-fix","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-unbound","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-unity","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-whitelist","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-eap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-generic","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-noauth","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-pam","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-pt-tls-client","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-starter","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-base","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-client","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-ifmap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-pdp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-server","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"}],"xenial":[{"name":"strongswan","version":"5.3.5-1ubuntu3.3","description":"IPsec VPN solution","is_source":true},{"name":"charon-cmd","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libcharon-extra-plugins","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libstrongswan","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libstrongswan-extra-plugins","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libstrongswan-standard-plugins","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-charon","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-ike","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-ikev1","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-ikev2","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-libcharon","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-nm","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-af-alg","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-agent","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-attr-sql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-certexpire","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-coupling","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-curl","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-dhcp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-dnscert","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-dnskey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-duplicheck","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-aka","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-aka-3gpp2","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-dynamic","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-gtc","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-md5","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-mschapv2","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-peap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-radius","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-sim","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-sim-file","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-sim-pcsc","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-pseudonym","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-reauth","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-sql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-tls","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-tnc","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-ttls","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-error-notify","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-farp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-fips-prf","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-gcrypt","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-gmp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-ipseckey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-kernel-libipsec","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-ldap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-led","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-load-tester","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-lookip","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-mysql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-ntru","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-openssl","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-pgp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-pkcs11","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-pubkey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-radattr","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-soup","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-sql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-sqlite","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-sshkey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-systime-fix","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-unbound","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-unity","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-whitelist","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-eap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-generic","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-noauth","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-pam","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-starter","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-base","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-client","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-ifmap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-pdp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-server","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"}],"yakkety":[{"name":"strongswan","version":"5.3.5-1ubuntu4.3","description":"IPsec VPN solution","is_source":true},{"name":"libstrongswan","version":"5.3.5-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu4.3"},{"name":"strongswan","version":"5.3.5-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu4.3"},{"name":"strongswan-plugin-gmp","version":"5.3.5-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu4.3"}],"zesty":[{"name":"strongswan","version":"5.5.1-1ubuntu3.1","description":"IPsec VPN solution","is_source":true},{"name":"libstrongswan","version":"5.5.1-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.5.1-1ubuntu3.1"},{"name":"strongswan","version":"5.5.1-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.5.1-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2017-9022","CVE-2017-9023"]}]},{"id":"CVE-2017-9022","published":"2017-05-30T12:00:00","updated_at":"2025-08-25T22:40:40.921545+00:00","description":"\nThe gmp plugin in strongSwan before 5.5.3 does not properly validate RSA\npublic keys before calling mpz_powm_sec, which allows remote peers to cause\na denial of service (floating point exception and process crash) via a\ncrafted certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3301-1","https://www.cve.org/CVERecord?id=CVE-2017-9022"],"bugs":[""],"patches":{"strongswan":[]},"tags":{},"packages":[{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"trusty","status":"released","description":"5.1.2-0ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"5.3.5-1ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"5.3.5-1ubuntu4.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"5.5.1-1ubuntu3.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3301-1"],"notices":[{"id":"USN-3301-1","title":"strongSwan vulnerabilities","summary":"strongSwan could be made to crash or hang if it received specially crafted\nnetwork traffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-05-30T13:03:09.563750","description":"It was discovered that the strongSwan gmp plugin incorrectly validated RSA\npublic keys. A remote attacker could use this issue to cause strongSwan to\ncrash, resulting in a denial of service. (CVE-2017-9022)\n\nIt was discovered that strongSwan incorrectly parsed ASN.1 CHOICE types. A\nremote attacker could use this issue to cause strongSwan to hang, resulting\nin a denial of service. (CVE-2017-9023)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"strongswan","version":"5.1.2-0ubuntu2.6","description":"IPsec VPN solution","is_source":true},{"name":"libstrongswan","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-ike","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-ikev1","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-ikev2","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-nm","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-af-alg","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-agent","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-attr-sql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-certexpire","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-coupling","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-curl","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-dhcp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-dnscert","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-dnskey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-duplicheck","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-aka","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-aka-3gpp2","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-dynamic","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-gtc","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-md5","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-mschapv2","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-peap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-radius","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-sim","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-sim-file","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-sim-pcsc","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-pseudonym","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-reauth","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-sql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-tls","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-tnc","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-eap-ttls","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-error-notify","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-farp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-fips-prf","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-gcrypt","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-gmp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-ipseckey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-kernel-libipsec","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-ldap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-led","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-load-tester","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-lookip","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-mysql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-ntru","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-openssl","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-pgp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-pkcs11","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-pubkey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-radattr","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-soup","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-sql","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-sqlite","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-sshkey","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-systime-fix","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-unbound","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-unity","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-whitelist","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-eap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-generic","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-noauth","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-plugin-xauth-pam","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-pt-tls-client","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-starter","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-base","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-client","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-ifmap","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-pdp","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"},{"name":"strongswan-tnc-server","version":"5.1.2-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.1.2-0ubuntu2.6","pocket":"security"}],"xenial":[{"name":"strongswan","version":"5.3.5-1ubuntu3.3","description":"IPsec VPN solution","is_source":true},{"name":"charon-cmd","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libcharon-extra-plugins","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libstrongswan","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libstrongswan-extra-plugins","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"libstrongswan-standard-plugins","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-charon","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-ike","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-ikev1","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-ikev2","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-libcharon","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-nm","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-af-alg","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-agent","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-attr-sql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-certexpire","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-coupling","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-curl","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-dhcp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-dnscert","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-dnskey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-duplicheck","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-aka","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-aka-3gpp2","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-dynamic","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-gtc","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-md5","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-mschapv2","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-peap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-radius","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-sim","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-sim-file","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-sim-pcsc","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-pseudonym","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-reauth","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-simaka-sql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-tls","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-tnc","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-eap-ttls","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-error-notify","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-farp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-fips-prf","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-gcrypt","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-gmp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-ipseckey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-kernel-libipsec","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-ldap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-led","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-load-tester","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-lookip","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-mysql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-ntru","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-openssl","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-pgp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-pkcs11","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-pubkey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-radattr","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-soup","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-sql","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-sqlite","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-sshkey","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-systime-fix","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-unbound","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-unity","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-whitelist","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-eap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-generic","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-noauth","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-plugin-xauth-pam","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-starter","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-base","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-client","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-ifmap","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-pdp","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"},{"name":"strongswan-tnc-server","version":"5.3.5-1ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu3.3","pocket":"security"}],"yakkety":[{"name":"strongswan","version":"5.3.5-1ubuntu4.3","description":"IPsec VPN solution","is_source":true},{"name":"libstrongswan","version":"5.3.5-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu4.3"},{"name":"strongswan","version":"5.3.5-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu4.3"},{"name":"strongswan-plugin-gmp","version":"5.3.5-1ubuntu4.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.3.5-1ubuntu4.3"}],"zesty":[{"name":"strongswan","version":"5.5.1-1ubuntu3.1","description":"IPsec VPN solution","is_source":true},{"name":"libstrongswan","version":"5.5.1-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.5.1-1ubuntu3.1"},{"name":"strongswan","version":"5.5.1-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.5.1-1ubuntu3.1"}]},"type":"USN","cves_ids":["CVE-2017-9022","CVE-2017-9023"]}]},{"id":"CVE-2017-7511","published":"2017-05-30T00:00:00","updated_at":"2025-08-25T22:37:48.884672+00:00","description":"\npoppler since version 0.17.3 has been vulnerable to NULL pointer\ndereference in pdfunite triggered by specially crafted documents.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"crash in cli tool"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3350-1","https://www.cve.org/CVERecord?id=CVE-2017-7511"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863759","https://bugs.freedesktop.org/show_bug.cgi?id=101149","https://bugs.freedesktop.org/show_bug.cgi?id=101153"],"patches":{"poppler":["upstream: https://cgit.freedesktop.org/poppler/poppler/commit/?id=5c9b08a875b07853be6c44e43ff5f7f059df666a"]},"tags":{},"packages":[{"name":"poppler","source":"https://ubuntu.com/security/cve?package=poppler","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=poppler","debian":"https://tracker.debian.org/pkg/poppler","statuses":[{"release_codename":"trusty","status":"released","description":"0.24.5-2ubuntu4.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.41.0-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"0.44.0-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"0.48.0-2ubuntu2.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3350-1"],"notices":[{"id":"USN-3350-1","title":"poppler vulnerabilities","summary":"poppler could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-07T14:45:36.232540","description":"Aleksandar Nikolic discovered that poppler incorrectly handled JPEG 2000\nimages. If a user or automated system were tricked into opening a crafted\nPDF file, an attacker could cause a denial of service or possibly execute\narbitrary code with privileges of the user invoking the program.\n(CVE-2017-2820)\n\nJiaqi Peng discovered that the poppler pdfunite tool incorrectly parsed\ncertain malformed PDF documents. If a user or automated system were tricked\ninto opening a crafted PDF file, an attacker could cause poppler to crash,\nresulting in a denial of service. (CVE-2017-7511)\n\nIt was discovered that the poppler pdfunite tool incorrectly parsed certain\nmalformed PDF documents. If a user or automated system were tricked into\nopening a crafted PDF file, an attacker could cause poppler to hang,\nresulting in a denial of service. (CVE-2017-7515)\n\nIt was discovered that poppler incorrectly handled JPEG 2000 images. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause cause poppler to crash, resulting in a denial of\nservice. (CVE-2017-9083)\n\nIt was discovered that poppler incorrectly handled memory when processing\nPDF documents. If a user or automated system were tricked into opening a\ncrafted PDF file, an attacker could cause poppler to consume resources,\nresulting in a denial of service. (CVE-2017-9406, CVE-2017-9408)\n\nAlberto Garcia, Francisco Oca, and Suleman Ali discovered that the poppler\npdftocairo tool incorrectly parsed certain malformed PDF documents. If a\nuser or automated system were tricked into opening a crafted PDF file, an\nattacker could cause poppler to crash, resulting in a denial of service.\n(CVE-2017-9775)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"poppler","version":"0.24.5-2ubuntu4.5","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-glib8","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"libpoppler44","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"},{"name":"poppler-utils","version":"0.24.5-2ubuntu4.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.5","pocket":"security"}],"xenial":[{"name":"poppler","version":"0.41.0-0ubuntu1.2","description":"PDF rendering library","is_source":true},{"name":"gir1.2-poppler-0.18","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-cpp0","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib-doc","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-glib8","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-private-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-4","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt4-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-1","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler-qt5-dev","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"libpoppler58","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"},{"name":"poppler-utils","version":"0.41.0-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.2","pocket":"security"}],"yakkety":[{"name":"poppler","version":"0.44.0-3ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"libpoppler61","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"},{"name":"poppler-utils","version":"0.44.0-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.44.0-3ubuntu2.1"}],"zesty":[{"name":"poppler","version":"0.48.0-2ubuntu2.1","description":"PDF rendering library","is_source":true},{"name":"libpoppler-cpp0v5","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-glib8","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt4-4","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler-qt5-1","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"libpoppler64","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"},{"name":"poppler-utils","version":"0.48.0-2ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/poppler","version_link":"https://launchpad.net/ubuntu/+source/poppler/0.48.0-2ubuntu2.1"}]},"type":"USN","cves_ids":["CVE-2017-2820","CVE-2017-7511","CVE-2017-7515","CVE-2017-9083","CVE-2017-9406","CVE-2017-9408","CVE-2017-9775"]}]},{"id":"CVE-2017-7502","published":"2017-05-30T00:00:00","updated_at":"2025-08-25T22:37:48.884672+00:00","description":"\nNull pointer dereference vulnerability in NSS since 3.24.0 was found when\nserver receives empty SSLv2 messages resulting into denial of service by\nremote attacker.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3336-1","https://ubuntu.com/security/notices/USN-3372-1","https://www.cve.org/CVERecord?id=CVE-2017-7502"],"bugs":[""],"patches":{"nss":["upstream: https://hg.mozilla.org/projects/nss/rev/55ea60effd0d"]},"tags":{},"packages":[{"name":"nss","source":"https://ubuntu.com/security/cve?package=nss","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nss","debian":"https://tracker.debian.org/pkg/nss","statuses":[{"release_codename":"trusty","status":"released","description":"2:3.28.4-0ubuntu0.14.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:3.28.4-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2:3.28.4-0ubuntu0.16.10.2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2:3.28.4-0ubuntu0.17.04.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3372-1","USN-3336-1"],"notices":[{"id":"USN-3372-1","title":"NSS vulnerability","summary":"Several security issues were fixed in NSS.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use NSS, such as Evolution and Chromium, to make all the necessary\nchanges.\n","references":[],"published":"2017-07-31T13:47:26.244969","description":"It was discovered that NSS incorrectly handled certain empty SSLv2\nmessages. A remote attacker could possibly use this issue to cause NSS to\ncrash, resulting in a denial of service. (CVE-2017-7502)\n\nKarthik Bhargavan and Gaetan Leurent discovered that the DES and Triple DES\nciphers were vulnerable to birthday attacks. A remote attacker could\npossibly use this flaw to obtain clear text data from long encrypted\nsessions. This update causes NSS to limit use of the same symmetric key.\n(CVE-2016-2183)\n\nIt was discovered that NSS incorrectly handled Base64 decoding. A remote\nattacker could use this flaw to cause NSS to crash, resulting in a denial\nof service, or possibly execute arbitrary code. (CVE-2017-5461)\n","is_hidden":false,"release_packages":{"precise":[{"name":"nss","version":"2:3.28.4-0ubuntu0.12.04.1","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.28.4-0ubuntu0.12.04.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.12.04.1"}]},"type":"USN","cves_ids":["CVE-2017-7502","CVE-2016-2183","CVE-2017-5461"]},{"id":"USN-3336-1","title":"NSS vulnerability","summary":"NSS could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"After a standard system update you need to restart any applications\nthat use NSS, such as Evolution and Chromium, to make all the necessary\nchanges.\n","references":[],"published":"2017-06-21T16:35:25.821289","description":"It was discovered that NSS incorrectly handled certain empty SSLv2\nmessages. A remote attacker could possibly use this issue to cause NSS to\ncrash, resulting in a denial of service.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"nss","version":"2:3.28.4-0ubuntu0.14.04.2","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.28.4-0ubuntu0.14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-1d","version":"2:3.28.4-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-dev","version":"2:3.28.4-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-nssdb","version":"2:3.28.4-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.14.04.2","pocket":"security"},{"name":"libnss3-tools","version":"2:3.28.4-0ubuntu0.14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.14.04.2","pocket":"security"}],"xenial":[{"name":"nss","version":"2:3.28.4-0ubuntu0.16.04.2","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.28.4-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.16.04.2","pocket":"security"},{"name":"libnss3-1d","version":"2:3.28.4-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.16.04.2","pocket":"security"},{"name":"libnss3-dev","version":"2:3.28.4-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.16.04.2","pocket":"security"},{"name":"libnss3-nssdb","version":"2:3.28.4-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.16.04.2","pocket":"security"},{"name":"libnss3-tools","version":"2:3.28.4-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.16.04.2","pocket":"security"}],"yakkety":[{"name":"nss","version":"2:3.28.4-0ubuntu0.16.10.2","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.28.4-0ubuntu0.16.10.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.16.10.2"}],"zesty":[{"name":"nss","version":"2:3.28.4-0ubuntu0.17.04.2","description":"Network Security Service library","is_source":true},{"name":"libnss3","version":"2:3.28.4-0ubuntu0.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nss","version_link":"https://launchpad.net/ubuntu/+source/nss/2:3.28.4-0ubuntu0.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-7502"]}]},{"id":"CVE-2017-9301","published":"2017-05-29T19:29:00","updated_at":"2025-08-26T12:02:23.808190+00:00","description":"\nplugins\\audio_filter\\libmpgatofixed32_plugin.dll in VideoLAN VLC media\nplayer 2.2.4 allows remote attackers to cause a denial of service (invalid\nread and application crash) or possibly have unspecified other impact via a\ncrafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"fixes not available as of 2017-08-01"},{"author":"mikesalvatore","note":"fixes not available as of 2018-10-23"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://code610.blogspot.com/2017/04/multiple-crashes-in-vlc-224.html","https://www.cve.org/CVERecord?id=CVE-2017-9301"],"bugs":[""],"patches":{"vlc":[]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"xenial","status":"deferred","description":"2019-04-23","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.5.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.0.3-1-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9300","published":"2017-05-29T19:29:00","updated_at":"2025-08-25T22:41:14.153089+00:00","description":"\nplugins\\codec\\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows\nremote attackers to cause a denial of service (heap corruption and\napplication crash) or possibly have unspecified other impact via a crafted\nFLAC file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://code610.blogspot.com/2017/04/multiple-crashes-in-vlc-224.html","https://www.cve.org/CVERecord?id=CVE-2017-9300"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/vlc/+bug/1709420"],"patches":{"vlc":["upstream: https://git.videolan.org/?p=vlc/vlc-2.2.git;a=commit;h=55a82442cfea9dab8b853f3a4610f2880c5fadf3"]},"tags":{},"packages":[{"name":"vlc","source":"https://ubuntu.com/security/cve?package=vlc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vlc","debian":"https://tracker.debian.org/pkg/vlc","statuses":[{"release_codename":"trusty","status":"released","description":"2.1.6-0ubuntu14.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.2.2-5ubuntu0.16.04.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.2.4-14ubuntu2.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-9299","published":"2017-05-29T19:29:00","updated_at":"2025-08-25T22:41:14.153089+00:00","description":"\nOpen Ticket Request System (OTRS) 3.3.9 has XSS in\nindex.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and\nDirection=[XSS] attacks. NOTE: this CVE may have limited relevance because\nit represents a 2017 discovery of an issue in software from 2014. The\n3.3.20 release, for example, is not affected.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://code610.blogspot.com/2017/05/turnkey-feat-otrs.html","https://www.cve.org/CVERecord?id=CVE-2017-9299"],"bugs":[""],"patches":{"otrs2":[]},"tags":{},"packages":[{"name":"otrs2","source":"https://ubuntu.com/security/cve?package=otrs2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=otrs2","debian":"https://tracker.debian.org/pkg/otrs2","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.0.7-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"5.0.7-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"5.0.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.3.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"5.0.7-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10377","published":"2017-05-29T04:29:00","updated_at":"2025-08-25T21:53:25.358643+00:00","description":"\nIn Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to\nread past the end of the packet buffer due to an unsigned integer underflow\nin `lib/flow.c` in the function `miniflow_extract`, permitting remote\nbypass of the access control list enforced by the switch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://mail.openvswitch.org/pipermail/ovs-dev/2016-July/319503.html","https://www.cve.org/CVERecord?id=CVE-2016-10377"],"bugs":[""],"patches":{"openvswitch":[]},"tags":{},"packages":[{"name":"openvswitch","source":"https://ubuntu.com/security/cve?package=openvswitch","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openvswitch","debian":"https://tracker.debian.org/pkg/openvswitch","statuses":[{"release_codename":"upstream","status":"released","description":"2.6.1+git20161123-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"2.5.2-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"2.6.1-0ubuntu0.16.10.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.6.1-0ubuntu5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":56760,"limit":20,"total_results":79316}