{"cves":[{"id":"CVE-2015-8625","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nMediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and\n1.26.x before 1.26.1 do not properly sanitize parameters when calling the\ncURL library, which allows remote attackers to read arbitrary files via an\n@ (at sign) character in unspecified POST array parameters.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T118032","https://www.cve.org/CVERecord?id=CVE-2015-8625"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8624","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nThe User::matchEditToken function in includes/User.php in MediaWiki before\n1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before\n1.26.1 does not perform token comparison in constant time before\ndetermining if a debugging message should be logged, which allows remote\nattackers to guess the edit token and bypass CSRF protection via a timing\nattack, a different vulnerability than CVE-2015-8623.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T119309","https://www.cve.org/CVERecord?id=CVE-2015-8624"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8623","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nThe User::matchEditToken function in includes/User.php in MediaWiki before\n1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in\nconstant time before returning, which allows remote attackers to guess the\nedit token and bypass CSRF protection via a timing attack, a different\nvulnerability than CVE-2015-8624.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gerrit.wikimedia.org/r/#/c/156336/5/includes/User.php","https://www.cve.org/CVERecord?id=CVE-2015-8623"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8622","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nCross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12,\n1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when\nis configured with a relative URL, allows remote authenticated users to\ninject arbitrary web script or HTML via wikitext, as demonstrated by a\nwikilink to a page named \"javascript:alert('XSS!').\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T117899","https://www.cve.org/CVERecord?id=CVE-2015-8622"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-0855","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:33:11.212550+00:00","description":"\nThe _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95\nallows attackers to execute arbitrary code via shell metacharacters in a\nfile path.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://git.gnome.org/browse/pitivi/commit/?id=45a4c84edb3b4343f199bba1c65502e3f49f5bb2 (RELEASE-0_95_0)","https://www.cve.org/CVERecord?id=CVE-2015-0855"],"bugs":["https://launchpad.net/bugs/1495272"],"patches":{"pitivi":["upstream: https://git.gnome.org/browse/pitivi/commit/?id=45a4c84edb3b4343f199bba1c65502e3f49f5bb2","other: https://bugs.launchpad.net/ubuntu/+source/pitivi/+bug/1495272/+attachment/4463293/+files/CVE-2015-0855.patch"]},"tags":{},"packages":[{"name":"pitivi","source":"https://ubuntu.com/security/cve?package=pitivi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=pitivi","debian":"https://tracker.debian.org/pkg/pitivi","statuses":[{"release_codename":"artful","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"0.95-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9557","published":"2017-03-23T18:59:00","updated_at":"2025-08-25T22:14:14.123684+00:00","description":"\nInteger overflow in jas_image.c in JasPer before 1.900.25 allows remote\nattackers to cause a denial of service (application crash) via a crafted\nfile.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fix is too intrusive for stable releases, and there is no crash\nunless jasper is built with ASAN. For these reasons, we will not\nbe fixing this issue. Marking as ignored."}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/19/jasper-signed-integer-overflow-in-jas_image-c","https://www.cve.org/CVERecord?id=CVE-2016-9557"],"bugs":["https://github.com/mdadams/jasper/issues/67"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/d42b2388f7f8e0332c846675133acea151fc557a"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.900.25","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9399","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nThe calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote\nattackers to cause a denial of service (assertion failure) via unspecified\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00044-jasper-assert-calcstepsizes (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://www.cve.org/CVERecord?id=CVE-2016-9399"],"bugs":["https://github.com/mdadams/jasper/issues/83"],"patches":{"jasper":["upstream: https://github.com/jasper-software/jasper/commit/84d00fb29a22e360c2ff91bdc2cd81c288826bfc"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was deferred [2020-07-22]","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9398","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nThe jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows\nremote attackers to cause a denial of service (assertion failure) via\nunspecified vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/17/1","https://github.com/asarubbo/poc/blob/master/00023-jasper-assert-jpc_floorlog2 (testcase)","https://www.cve.org/CVERecord?id=CVE-2016-9398"],"bugs":["https://github.com/mdadams/jasper/issues/71"],"patches":{"jasper":["other: https://github.com/jasper-maint/jasper/pull/38"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was deferred [2020-07-22]","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9397","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nThe jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote\nattackers to cause a denial of service (assertion failure) via unspecified\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/11/17/1","https://github.com/asarubbo/poc/blob/master/00010-jasper-assert-jpc_dequantize (testcase)","https://www.cve.org/CVERecord?id=CVE-2016-9397"],"bugs":["https://github.com/mdadams/jasper/issues/56"],"patches":{"jasper":["upstream: https://github.com/jasper-software/jasper/commit/5185cb13da413f826dcc5f1e0c1eb3e038dc0874","upstream: https://github.com/jasper-software/jasper/commit/861e16ff941adad07e1ed2579765d86e8ba00bed"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was deferred [2020-07-22]","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9395","published":"2017-03-23T18:59:00","updated_at":"2025-08-25T22:13:45.279602+00:00","description":"\nThe jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows\nremote attackers to cause a denial of service (assertion failure) via a\ncrafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this change breaks ABI and can't be used in stable releases.\nWe will not be fixing this issue. Marking as ignored."}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/asarubbo/poc/blob/master/00043-jasper-assert-jas_matrix_t (testcase)","http://www.openwall.com/lists/oss-security/2016/11/17/1","https://www.cve.org/CVERecord?id=CVE-2016-9395"],"bugs":["https://github.com/mdadams/jasper/issues/82"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/d42b2388f7f8e0332c846675133acea151fc557a"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9276","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nThe dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before\n20161124 allows remote attackers to cause a denial of service\n(out-of-bounds read).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/libdwarf/code/ci/583f8834083b5ef834c497f5b47797e16101a9a6/","https://blogs.gentoo.org/ago/2016/11/07/libdwarf-heap-based-buffer-overflow-in-dwarf_get_aranges_list-dwarf_arange-c","https://www.cve.org/CVERecord?id=CVE-2016-9276"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844011"],"patches":{"dwarfutils":[]},"tags":{},"packages":[{"name":"dwarfutils","source":"https://ubuntu.com/security/cve?package=dwarfutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dwarfutils","debian":"https://tracker.debian.org/pkg/dwarfutils","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9275","published":"2017-03-23T18:59:00","updated_at":"2025-08-25T22:13:30.167109+00:00","description":"\nHeap-based buffer overflow in the _dwarf_skim_forms function in\nlibdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers\nto cause a denial of service (out-of-bounds read).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://sourceforge.net/p/libdwarf/code/ci/583f8834083b5ef834c497f5b47797e16101a9a6/","https://blogs.gentoo.org/ago/2016/11/07/libdwarf-heap-based-buffer-overflow-in-_dwarf_skim_forms-dwarf_macro5-c","https://www.cve.org/CVERecord?id=CVE-2016-9275"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844012"],"patches":{"dwarfutils":[]},"tags":{},"packages":[{"name":"dwarfutils","source":"https://ubuntu.com/security/cve?package=dwarfutils","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dwarfutils","debian":"https://tracker.debian.org/pkg/dwarfutils","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"20161124-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9266","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nlistmp3.c in libming 0.4.7 allows remote attackers to unspecified impact\nvia a crafted mp3 file, which triggers an invalid left shift.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/09/libming-listmp3-left-shift-in-listmp3-c","https://www.cve.org/CVERecord?id=CVE-2016-9266"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=843928"],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9265","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nThe printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote\nattackers to cause a denial of service (divide-by-zero error and\napplication crash) via a crafted mp3 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/09/libming-listmp3-divide-by-zero-in-printmp3headers-list","https://www.cve.org/CVERecord?id=CVE-2016-9265"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=843928"],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9264","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:29.978828+00:00","description":"\nBuffer overflow in the printMP3Headers function in listmp3.c in Libming\n0.4.7 allows remote attackers to cause a denial of service (out-of-bounds\nread) via a crafted mp3 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/07/libming-listmp3-global-buffer-overflow-in-printmp3headers-listmp3-c","https://www.cve.org/CVERecord?id=CVE-2016-9264"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=843928"],"patches":{"ming":[]},"tags":{},"packages":[{"name":"ming","source":"https://ubuntu.com/security/cve?package=ming","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ming","debian":"https://tracker.debian.org/pkg/ming","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-9262","published":"2017-03-23T18:59:00","updated_at":"2025-08-25T22:13:25.301428+00:00","description":"\nMultiple integer overflows in the (1) jas_realloc function in\nbase/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in\nJasPer before 1.900.22 allow remote attackers to cause a denial of service\nvia a crafted image, which triggers use after free vulnerabilities.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.900.18"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/11/07/jasper-use-after-free-in-jas_realloc-jas_malloc-c","https://www.cve.org/CVERecord?id=CVE-2016-9262","https://ubuntu.com/security/notices/USN-3693-1"],"bugs":["https://github.com/mdadams/jasper/issues/74"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/634ce8e8a5accc0fa05dd2c20d42b4749d4b2735"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":["USN-3693-1"],"notices":[{"id":"USN-3693-1","title":"JasPer vulnerabilities","summary":"Several security issues were fixed in JasPer.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-06-27T17:20:01.117220","description":"It was discovered that JasPer incorrectly handled certain malformed\nJPEG-2000 image files. If a user or automated system using JasPer were\ntricked into opening a specially crafted image, an attacker could exploit\nthis to cause a denial of service or possibly execute code with the\nprivileges of the user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"jasper","version":"1.900.1-14ubuntu3.5","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"},{"name":"libjasper1","version":"1.900.1-14ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-14ubuntu3.5","pocket":"security"}],"xenial":[{"name":"jasper","version":"1.900.1-debian1-2.4ubuntu1.2","description":"Library for manipulating JPEG-2000 files","is_source":true},{"name":"libjasper-dev","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper-runtime","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"},{"name":"libjasper1","version":"1.900.1-debian1-2.4ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jasper","version_link":"https://launchpad.net/ubuntu/+source/jasper/1.900.1-debian1-2.4ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-5203","CVE-2015-5221","CVE-2016-10248","CVE-2016-10250","CVE-2016-8883","CVE-2016-8887","CVE-2016-9262","CVE-2016-9387","CVE-2016-9388","CVE-2016-9389","CVE-2016-9390","CVE-2016-9391","CVE-2016-9392","CVE-2016-9393","CVE-2016-9394","CVE-2016-9396","CVE-2016-9600","CVE-2017-1000050","CVE-2017-6850"]}]},{"id":"CVE-2016-9011","published":"2017-03-23T18:59:00","updated_at":"2025-08-26T11:56:14.060909+00:00","description":"\nThe wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers\nto cause a denial of service (application crash) via a crafted wmf file,\nwhich triggers a memory allocation failure.","ubuntu_description":"","notes":[{"author":"leosilva","note":"debian fixed that with the debian proposed patch."}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/10/18/9","https://blogs.gentoo.org/ago/2016/10/18/libwmf-memory-allocation-failure-in-wmf_malloc-api-c","https://github.com/asarubbo/poc/blob/master/00015-libwmf-memalloc-wmf_malloc (reproducer)","https://bugs.debian.org/cgi-bin/bugreport.cgi?att=1;bug=842090;filename=libwmf-0.2.8.4-CVE-2016-9011-debian.patch;msg=10","https://www.cve.org/CVERecord?id=CVE-2016-9011"],"bugs":[""],"patches":{"libwmf":[]},"tags":{},"packages":[{"name":"libwmf","source":"https://ubuntu.com/security/cve?package=libwmf","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libwmf","debian":"https://tracker.debian.org/pkg/libwmf","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.2.8.4-10.6","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.2.8.4-12","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8886","published":"2017-03-23T18:59:00","updated_at":"2025-08-25T22:12:55.289561+00:00","description":"\nThe jas_malloc function in libjasper/base/jas_malloc.c in JasPer before\n1.900.11 allows remote attackers to have unspecified impact via a crafted\nfile, which triggers a memory allocation failure.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"upstream fix adds experimental memory allocator. Not suitable\nfor backporting to stable releases. No viable fix as of\n2019-01-17, but the memory allocation is handled gracefully, so\nthe security impact is minimal. We will not be fixing this issue.\nMarking as ignored."}],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/10/18/jasper-memory-allocation-failure-in-jas_malloc-jas_malloc-c","https://www.cve.org/CVERecord?id=CVE-2016-8886"],"bugs":["https://github.com/mdadams/jasper/issues/35"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/65536647d380571d1a9a6c91fa03775fb5bbd256"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-8885","published":"2017-03-23T18:59:00","updated_at":"2025-08-25T22:12:55.289561+00:00","description":"\nThe bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before\n1.900.9 allows remote attackers to cause a denial of service (NULL pointer\ndereference) by calling the imginfo command with a crafted BMP image.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Incomplete fix for CVE-2016-8690\nsame fix as CVE-2016-8884\nrelevant part included in 14_CVE-2016-10249.patch"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2016/10/18/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c-incomplete-fix-for-cve-2016-8690","https://www.cve.org/CVERecord?id=CVE-2016-8885"],"bugs":["https://github.com/mdadams/jasper/issues/33"],"patches":{"jasper":["upstream: https://github.com/mdadams/jasper/commit/5d66894d2313e3f3469f19066e149e08ff076698","vendor: https://git.centos.org/blob/rpms!jasper.git/94b862d2431727bf8937bddc216e5094fdb2e1c6/SOURCES!jasper-CVE-2016-8690-CVE-2016-8884-CVE-2016-8885.patch"]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.900.1-14ubuntu3.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.900.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.900.1-debian1-2.4ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10059","published":"2017-03-23T17:59:00","updated_at":"2025-08-25T21:52:18.321492+00:00","description":"\nBuffer overflow in coders/tiff.c in ImageMagick before 6.9.4-1 allows\nremote attackers to cause a denial of service (application crash) or have\nunspecified other impact via a crafted TIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0157-Fix-a-buffer-overlfow-in-tiff-file-handling.patch"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/12/20/3","https://www.cve.org/CVERecord?id=CVE-2016-10059"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=845195"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/58cf5bf4fade82e3b510e8f3463a967278a3e410"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.9.6.2+dfsg-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu8.2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":57700,"limit":20,"total_results":79316}